CVE-2019-14825 PUBLISHED CVSS 4.099999904632568 MEDIUM

A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.0.9. Registry credentials used during container image discovery were inadvertently logged without being masked. This flaw could expose the registry credentials to other privileged users.

EPSS 0.15% · 35.8th percentile

Risk Scores

CVSS v3.0
4.099999904632568
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
EPSS Score
0.15%
35.8th percentile

Affected Products

VendorProductVersions
theforemankatello3.0.0.0
RubyGemskatello3.0.0.0
Red Hatkatellokatello versions 3.x.x.x before katello 3.12.0.9

Timeline

References

Open in Interactive Console →