CVE-2016-4996

HIGH

Red Hat Satellite - Plaintext Root Password Exposure in Discovery-Debug Logs

Title source: llm
STIX 2.1

Description

discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local users with access to the system journal to obtain the root password by reading the system journal, or by clicking Logs on the console.

References (2)

Core 2
Core References
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:0336
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1349136

Scores

CVSS v3 7.0
EPSS 0.0031
EPSS Percentile 22.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-255
Status published
Products (1)
redhat/satellite 6.3
Published Jul 17, 2017
Tracked Since Feb 18, 2026