A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the process list and allows an attacker to take advantage and obtain the password.
References
Configurations
No configuration.
History
06 Jun 2024, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
05 Jun 2024, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-06-05 15:15
Updated : 2024-06-06 14:17
NVD link : CVE-2024-3716
Mitre link : CVE-2024-3716
CVE.ORG link : CVE-2024-3716
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
