Impact
A flaw in the insight-core credential redaction layer fails to detect credentials that are not directly labeled with the literal string 'password', allowing cleartext SSSD LDAP bind passwords and Pacemaker fence device credentials to be embedded in archives uploaded to console.redhat.com. The exposure of these credentials can facilitate lateral movement and privilege escalation for an attacker who gains access to the uploaded archive, compromising the security of the affected host and potentially the entire network. The weakness is a credential exposure flaw, mapped to CWE-312.
Affected Systems
The vulnerability impacts Red Hat Pen Drive Powered by Red Hat Lightspeed, Red Hat Certification Program for Red Hat Enterprise Linux 9 and 10, Red Hat Enterprise Linux 9 and 10, and Red Hat Satellite 6. Specific affected versions are not enumerated in the available data, so all current releases of these products should be considered potentially vulnerable.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability is classified as medium severity. EPSS data is unavailable and the flaw is not listed in the CISA KEV catalog. The likely attack vector involves an attacker either compromising the local host or substituting a malicious insights-core or exploiting the file upload function to capture an archive that contains these credentials. Once obtained, the cleartext passwords allow an adversary to authenticate to LDAP or Pacemaker fencing endpoints, potentially taking control of the node or the cluster.
OpenCVE Enrichment