A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the process list and allows an attacker to take advantage and obtain the password.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2024-06-05T15:05:37.869Z
Updated: 2024-09-25T14:15:16.773Z
Reserved: 2024-04-12T16:25:23.621Z
Link: CVE-2024-3716
Vulnrichment
Updated: 2024-08-01T20:20:00.926Z
NVD
Status : Modified
Published: 2024-06-05T15:15:12.043
Modified: 2024-11-21T09:30:13.927
Link: CVE-2024-3716
Redhat