PT-2019-16756 · Red Hat · Candlepin+1
Publicado
2019-04-12
·
Atualizado
2020-10-15
·
CVE-2019-3891
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Red Hat Satellite version 6.4
Description
A security issue was found in the Candlepin component of Red Hat Satellite, where a world-readable log file leaked the credentials of the Candlepin database. This could allow a malicious user with local access to a Satellite host to modify the database, preventing Satellite from fetching package updates and thereby preventing all Satellite hosts from accessing those updates.
Recommendations
For Red Hat Satellite version 6.4, ensure that the log file belonging to the Candlepin component is properly secured to prevent unauthorized access, and consider resetting the leaked credentials to prevent potential misuse.
Exploit
Correção
Insertion into Log File
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Candlepin
Red Hat Satellite