A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2023:7851 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:1061 | vendor advisory |
https://access.redhat.com/security/cve/CVE-2023-4886 | vdb entry vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2230135 | vendor advisory issue tracking |