Bug 1349136 (CVE-2016-4996) - CVE-2016-4996 foreman: inside discovery-debug, the root password is displayed in plaintext
Summary: CVE-2016-4996 foreman: inside discovery-debug, the root password is displayed...
Alias: CVE-2016-4996
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 1349138 1359469 1470445
Blocks: 1349141 1432305
TreeView+ depends on / blocked
Reported: 2016-06-22 19:06 UTC by Kurt Seifried
Modified: 2021-10-21 00:53 UTC (History)
12 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in discovery-debug in foreman. An attacker, with permissions to view the debug results, would be able to view the root password associated with that system, potentially allowing them to access it.
Clone Of:
Last Closed: 2021-10-21 00:53:40 UTC

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:0336 0 normal SHIPPED_LIVE Important: Satellite 6.3 security, bug fix, and enhancement update 2018-02-21 22:43:42 UTC

Description Kurt Seifried 2016-06-22 19:06:02 UTC
Thom Carlin of the Red Hat QCI QE Team reports:

Inside discovery-debug, the root password is displayed in plaintext. A
redacted sample:

"Discovered by URL: https://<<sat6_fqdn>>
Entering screen_ssh
TUI executing: echo 'root:<<plaintext_password>>' | chpasswd &&
systemctl restart sshd.service
Starting Stop Read-Ahead Data Collection...
Started Stop Read-Ahead Data Collection."

The output is also available on the console after discovery if you click
on Logs and scroll down

Comment 1 Kurt Seifried 2016-06-22 19:06:15 UTC

Name: Thom Carlin (Red Hat)

Comment 3 Lukas Zapletal 2016-06-23 11:12:31 UTC
Thanks for report, by default root account is locked on discovered nodes, user needs to enable ssh service manually and enter root password in the dialog. Then it makes into the system journal in clear text.

Comment 7 Lukas Zapletal 2016-06-24 11:41:44 UTC
Updating the dependant 6.1 bug to 6.2 release.

Comment 11 errata-xmlrpc 2018-02-21 12:27:46 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.3 for RHEL 7

Via RHSA-2018:0336 https://access.redhat.com/errata/RHSA-2018:0336

Note You need to log in before you can comment on or make changes to this bug.