The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password via an API request.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://projects.theforeman.org/issues/2069 | |
http://theforeman.org/security.html | vendor advisory |