A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the process list and allows an attacker to take advantage and obtain the password.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2024-3716 | third party advisory vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2274755 | third party advisory issue tracking |