Severity
8.8HIGH
EPSS
0.2%
top 61.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 21
Latest updateMay 13

Description

A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDtheforeman/foreman< 1.15
CVEListV5[unknown]/foremanforeman 1.15

🔴Vulnerability Details

2
GHSA
GHSA-82j5-w3wh-5hfm: A flaw was found in foreman before version 12022-05-13
CVEList
CVE-2017-2672: A flaw was found in foreman before version 12018-06-21

📋Vendor Advisories

1
Red Hat
foreman: Image password leak2017-04-04

💬Community

1
Bugzilla
CVE-2017-2672 foreman: Image password leak2017-04-06