PT-2019-16756 · Red Hat · Candlepin+1

Publicado

2019-04-12

·

Atualizado

2020-10-15

·

CVE-2019-3891

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Red Hat Satellite version 6.4
Description A security issue was found in the Candlepin component of Red Hat Satellite, where a world-readable log file leaked the credentials of the Candlepin database. This could allow a malicious user with local access to a Satellite host to modify the database, preventing Satellite from fetching package updates and thereby preventing all Satellite hosts from accessing those updates.
Recommendations For Red Hat Satellite version 6.4, ensure that the log file belonging to the Candlepin component is properly secured to prevent unauthorized access, and consider resetting the leaked credentials to prevent potential misuse.

Exploit

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-3891
RHSA-2019:1222

Produtos afetados

Candlepin
Red Hat Satellite