PT-2024-19170 · Suse · Suse Manager Server+1

Cédric Bosdonnat

·

Published

2024-11-18

·

Updated

2025-02-14

·

CVE-2024-22037

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SUSE Manager Server (affected versions not specified)
Description The issue concerns the exposure of sensitive system information due to the uyuni-server-attestation systemd service needing a database password environment variable. Although the file containing this variable has 640 permission and cannot be directly shown to users, the environment is still exposed by systemd to non-privileged users, potentially leading to unauthorized access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-22037
OPENSUSE-SU-2025_0525-1
SUSE-RU-2024:4008-1
SUSE-SU-2025:0524-1
SUSE-SU-2025:0525-1
SUSE-SU-2025:0532-1
SUSE-SU-2025:20124-1

Affected Products

Suse Manager Server
Suse