SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-3893

In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource.

MEDIUM 4.9EPSS 1.83%

Does this matter?

Lower severity and a low EPSS score (1.83%). Track it; it rarely justifies an emergency change on its own.

Description

In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user with the "delete_compute_resource" permission can use this flaw to take control over compute resources managed by foreman. Versions before 1.20.3, 1.21.1, 1.22.0 are vulnerable.

CVSS 3.1
4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS
1.83% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-732
Affected
theforeman/foreman · redhat/satellite
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.