6.7 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): HIGH
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
Foreman: world readable file containing secrets
A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.
References
Affected products
- *
- ==3.8.0
- *
Matching in nixpkgs
pkgs.foreman
Process manager for applications with multiple components
pkgs.emacsPackages.foreman-mode
None
-
nixos-unstable 20170725.1422
- nixpkgs-unstable 20170725.1422
- nixos-unstable-small 20170725.1422
Package maintainers
-
@zimbatm zimbatm <zimbatm@zimbatm.com>