CVE-2020-14334
published 2020-07-31CVE-2020-14334: A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain complete…
PriorityP345high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.32%
23.6th percentile
A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain complete control of the Satellite instance.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cjmx-h785-pr4r: A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files
ghsa_unreviewed·2022-05-24
CVE-2020-14334 [MEDIUM] CWE-522 GHSA-cjmx-h785-pr4r: A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files
A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain complete control of the Satellite instance.
Red Hat
foreman: unauthorized cache read on RPM-based installations through local user
vendor_redhat·2020-07-28·CVSS 8.8
CVE-2020-14334 [HIGH] CWE-522 foreman: unauthorized cache read on RPM-based installations through local user
foreman: unauthorized cache read on RPM-based installations through local user
A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain complete control of the Satellite instance.
A flaw was found in Red Hat Satellite. An attacker could gain access to cache files further allowing access to cached credentials that could help the attacker to gain complete control of the Satellite instance. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Mitigation: This flaw can be mitigated by manually changing the directory permissions to remove readable bits for the others:
# chmod 0750 /run/foreman
No detection rules found.
No public exploits indexed.
2020-07-31
Published