VDB
CVE-2017-2672
CVE-2017-2672
PUBLISHED
CVSS 6.5 MEDIUM
Reported by redhat · Published June 21, 2018
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.
Risk Scores
CVSS v3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| [UNKNOWN] | foreman | foreman 1.15 |
| [UNKNOWN] | foreman | * |
Timeline
- Jun 21, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 22, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 25, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 27, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 2, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 5, 2022 EPSS Score
- Jan 7, 2023 EPSS Score
References
- x_refsource_CONFIRM
- RHSA-2018:0336 vendor-advisoryx_refsource_REDHAT
- 97526 vdb-entryx_refsource_BID
- x_refsource_CONFIRM