CVE-2019-3893 PUBLISHED CVSS 4.9 MEDIUM

Reported by redhat · Published April 9, 2019

In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user with the "delete_compute_resource" permission can use this flaw to take control over compute resources managed by foreman. Versions before 1.20.3, 1.21.1, 1.22.0 are vulnerable.

Risk Scores

CVSS v3.0
4.9
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
The Foreman Projectforeman1.20.3, 1.21.1, 1.22.0
The Foreman Projectforeman1.20.3, 1.21.1, 1.22.0

Timeline

References

Open in Interactive Console →