CVE-2017-2672

MEDIUM

Foreman < 1.15 - Unprotected Credential Exposure in Image Provisioning Logs

Title source: llm
STIX 2.1

Description

A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.

References (4)

Core 4
Core References
Exploit, Vendor Advisory x_refsource_confirm
https://projects.theforeman.org/issues/19169
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:0336
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97526
Exploit, Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2672

Scores

CVSS v3 6.5
EPSS 0.0122
EPSS Percentile 64.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-269 CWE-312
Status published
Products (2)
redhat/satellite 6.3
theforeman/foreman < 1.15
Published Jun 21, 2018
Tracked Since Feb 18, 2026