PT-2019-16756 · Red Hat · Candlepin+1
Published
2019-04-12
·
Updated
2020-10-15
·
CVE-2019-3891
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Red Hat Satellite version 6.4
Description
A security issue was found in the Candlepin component of Red Hat Satellite, where a world-readable log file leaked the credentials of the Candlepin database. This could allow a malicious user with local access to a Satellite host to modify the database, preventing Satellite from fetching package updates and thereby preventing all Satellite hosts from accessing those updates.
Recommendations
For Red Hat Satellite version 6.4, ensure that the log file belonging to the Candlepin component is properly secured to prevent unauthorized access, and consider resetting the leaked credentials to prevent potential misuse.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Candlepin
Red Hat Satellite