foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those systems.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/94985 | vdb entry third party advisory |
https://access.redhat.com/errata/RHSA-2018:0336 | third party advisory vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9593 | issue tracking third party advisory |