Pavel Moravec of Red Hat reports:
It was found that foreman-debug did not obfuscate sensitive information (such as passwords) from the katello-installer log file, allowing a user authorized to access the log files created by foreman-debug to gain access to potentially sensitive information.
Name: Pavel Moravec (Red Hat)
Please associate this CVE with this BZ which is already tracking more things our filters do not catch:
The linked one will be either closed as dupe or changed to installer (different problem).
This will be fixed in Foreman 1.15 and Satellite 6.3.
This issue has been addressed in the following products:
Red Hat Satellite 6.3 for RHEL 7
Via RHSA-2018:0336 https://access.redhat.com/errata/RHSA-2018:0336