4
CVSSv2

CVE-2019-3893

Published: 09/04/2019 Updated: 30/11/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

In Foreman it exists that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user with the "delete_compute_resource" permission can use this flaw to take control over compute resources managed by foreman. Versions prior to 1.20.3, 1.21.1, 1.22.0 are vulnerable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

theforeman foreman

redhat satellite 6.0

Vendor Advisories

Impact: Moderate Public Date: 2019-04-09 CWE: CWE-200 Bugzilla: 1696400: CVE-2019-3893 foreman: Recover ...