Untriaged
Permalink
CVE-2023-4886
6.7 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): HIGH
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
Foreman: world readable file containing secrets
A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.
References
Affected products
foreman
- ==3.8.0
- *
foreman-installer
- *
Matching in nixpkgs
pkgs.foreman
Process manager for applications with multiple components
pkgs.emacsPackages.foreman-mode
None
-
nixos-unstable 20170725.1422
- nixpkgs-unstable 20170725.1422
- nixos-unstable-small 20170725.1422
Package maintainers
-
@zimbatm zimbatm <zimbatm@zimbatm.com>