PT-2023-30988 · Apache+1 · Apache Tomcat+1

Pedro Sampaio

·

Published

2023-10-03

·

Updated

2025-03-26

·

CVE-2023-4886

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions foreman (affected versions not specified)
Description A sensitive information exposure issue was found in foreman, where the contents of tomcat's server.xml file are world readable. This file contains passwords to candlepin's keystore and truststore.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2025-3716
CVE-2023-4886
RHSA-2023:7851
RHSA-2024:1061

Affected Products

Alt Linux
Apache Tomcat