CVE-2016-4996
published 2017-07-17CVE-2016-4996: discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal…
PriorityP430high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
0.31%
22.7th percentile
discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local users with access to the system journal to obtain the root password by reading the system journal, or by clicking Logs on the console.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jwrm-9f5g-qmp3: discovery-debug in Foreman before 6
ghsa_unreviewed·2022-05-14
CVE-2016-4996 [HIGH] GHSA-jwrm-9f5g-qmp3: discovery-debug in Foreman before 6
discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local users with access to the system journal to obtain the root password by reading the system journal, or by clicking Logs on the console.
Red Hat
foreman: inside discovery-debug, the root password is displayed in plaintext
vendor_redhat·2016-06-22·CVSS 7.0
CVE-2016-4996 [HIGH] CWE-532 foreman: inside discovery-debug, the root password is displayed in plaintext
foreman: inside discovery-debug, the root password is displayed in plaintext
discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local users with access to the system journal to obtain the root password by reading the system journal, or by clicking Logs on the console.
A flaw was found in discovery-debug in foreman. An attacker, with permissions to view the debug results, would be able to view the root password associated with that system, potentially allowing them to access it.
Package: foreman (Red Hat Ceph Storage 1.3) - Will not fix
No detection rules found.
No public exploits indexed.
2017-07-17
Published