PT-2022-8319 · Red Hat+1 · Red Hat Satellite+1

Published

2020-03-03

·

Updated

2022-12-08

·

CVE-2020-10710

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Satellite (affected versions not specified)
Description A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges, such as root, to retrieve the Candlepin plaintext password.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1418
ALT-PU-2020-2200
CVE-2020-10710

Affected Products

Alt Linux
Red Hat Satellite