CVE-2020-14371
published 2021-06-02CVE-2020-14371: A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are running on these…
PriorityP431medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.87%
54.5th percentile
A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are running on these resources in Satellite.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Satellite: Compute resource credential leak
vendor_redhat·2020-08-27·CVSS 6.5
CVE-2020-14371 [MEDIUM] CWE-200 Satellite: Compute resource credential leak
Satellite: Compute resource credential leak
A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are running on these resources in Satellite.
A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are running on these resources in Satellite.
Statement: Red Hat Satellite is vulnerable to the compute resource credential leak through VMs that are running on these resources in Satellite. Red Hat Product Security has rated this flaw as having a security impact of Moderate. Please refer to https://access.redhat.com/security/updates/classification for clarification on the scoring.
Package: foreman (Red Hat Satellite 6) - Will not fix
Red Hat
Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371
vendor_redhat·2020-02-20·CVSS 7.5
CVE-2020-6950 [HIGH] CWE-22 Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371
Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
A flaw was found in Eclipse Mojarra before version 2.3.14, where it is vulnerable to a path traversal flaw via the loc parameter or the con parameter. An attacker could exploit this flaw to read arbitrary files.
Mitigation: There is no currently known mitigation for this flaw.
Package: jsf-impl (Red Hat Decision Manager 7) - Not affected
Package: jsf-impl (Red Hat JBoss Enterprise Application Platform 6) - Out of support scope
Package: jsf-impl (Red Hat JBoss Fuse 6) - Out of support scope
Package: jsf-impl (Red Hat JBoss Fuse Service Works 6) -
GHSA
GHSA-cwhp-2whx-784h: A credential leak vulnerability was found in Red Hat Satellite
ghsa_unreviewed·2022-05-24
CVE-2020-14371 [MEDIUM] CWE-200 GHSA-cwhp-2whx-784h: A credential leak vulnerability was found in Red Hat Satellite
A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are running on these resources in Satellite.
No detection rules found.
No public exploits indexed.
2021-06-02
Published