Impact
This vulnerability enables a local attacker to glean a Red Hat Subscription Management offline token that is exposed in the command line of a helper script during token validation. The flaw occurs when the token is passed as a process argument, allowing process metadata inspection to retrieve the token value. The exposed token can be used to obtain access tokens, thereby compromising confidentiality of subscription data. This weakness corresponds to CWE-214, involving improper removal of sensitive information from process metadata.
Affected Systems
Affected systems include Red Hat Enterprise Linux 10 and Red Hat Enterprise Linux 9. The vulnerability is present in the cockpit‑machines service that ships with these operating system releases.
Risk and Exploitability
The vulnerability is rated with a CVSS score of 5, indicating moderate severity. EPSS data is not available, so the probability of exploitation is uncertain. It is not listed in the CISA KEV catalog. The likely attack vector is local, requiring the attacker to have the ability to inspect process metadata, which typically requires privileged access or compromise of a local account. With this access, the attacker can expose the offline token and use it to request new access tokens.
OpenCVE Enrichment