VDB

CVE-2017-2672

CVE-2017-2672 PUBLISHED CVSS 6.5 MEDIUM

Reported by redhat · Published June 21, 2018

A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.

Risk Scores

CVSS v3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
[UNKNOWN]foremanforeman 1.15
[UNKNOWN]foreman*

Timeline

  • Jun 21, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 22, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 25, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 27, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 2, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 5, 2022 EPSS Score
  • Jan 7, 2023 EPSS Score

References

  • x_refsource_CONFIRM
  • RHSA-2018:0336 vendor-advisoryx_refsource_REDHAT
  • 97526 vdb-entryx_refsource_BID
  • x_refsource_CONFIRM
Open in Interactive Console →
$ Console Community · 100/wk Open console ›