A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/theforeman/foreman/pull/5369 | third party advisory issue tracking |
https://bugzilla.redhat.com/show_bug.cgi?id=1561723 | third party advisory issue tracking |
https://access.redhat.com/errata/RHSA-2018:2927 | third party advisory vendor advisory |
https://projects.theforeman.org/issues/22546 | vendor advisory issue tracking |