A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Mar 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 15 Mar 2025 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | foreman: Disclosure of Executed Commands and Outputs in Foreman / Red Hat Satellite | Foreman: disclosure of executed commands and outputs in foreman / red hat satellite |
First Time appeared |
Redhat
Redhat satellite |
|
CPEs | cpe:/a:redhat:satellite:6 | |
Vendors & Products |
Redhat
Redhat satellite |
|
References |
|
Fri, 14 Mar 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively. | |
Title | foreman: Disclosure of Executed Commands and Outputs in Foreman / Red Hat Satellite | |
Weaknesses | CWE-922 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-03-17T16:53:13.910Z
Reserved: 2025-03-10T12:20:21.761Z
Link: CVE-2025-2157

Updated: 2025-03-17T16:53:10.618Z

Status : Received
Published: 2025-03-15T07:15:34.930
Modified: 2025-03-15T07:15:34.930
Link: CVE-2025-2157
