A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the process list and allows an attacker to take advantage and obtain the password.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-02-08T03:12:06.141Z
Reserved: 2024-04-12T16:25:23.621Z
Link: CVE-2024-3716

Updated: 2024-08-01T20:20:00.926Z

Status : Modified
Published: 2024-06-05T15:15:12.043
Modified: 2024-11-21T09:30:13.927
Link: CVE-2024-3716
