PT-2019-16756 · Red Hat · Candlepin+1

Published

2019-04-12

·

Updated

2020-10-15

·

CVE-2019-3891

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Red Hat Satellite version 6.4
Description A security issue was found in the Candlepin component of Red Hat Satellite, where a world-readable log file leaked the credentials of the Candlepin database. This could allow a malicious user with local access to a Satellite host to modify the database, preventing Satellite from fetching package updates and thereby preventing all Satellite hosts from accessing those updates.
Recommendations For Red Hat Satellite version 6.4, ensure that the log file belonging to the Candlepin component is properly secured to prevent unauthorized access, and consider resetting the leaked credentials to prevent potential misuse.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-3891
RHSA-2019:1222

Affected Products

Candlepin
Red Hat Satellite