Bug 2274755 (CVE-2024-3716) - CVE-2024-3716 foreman-installer: Candlepin database password being leaked to local users via the process list
Summary: CVE-2024-3716 foreman-installer: Candlepin database password being leaked to ...
Keywords:
Status: NEW
Alias: CVE-2024-3716
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2274758 2274759 2274760
Blocks: 2274756
TreeView+ depends on / blocked
 
Reported: 2024-04-12 17:39 UTC by Pedro Sampaio
Modified: 2024-09-05 18:13 UTC (History)
14 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the process list and allows an attacker to take advantage and obtain the password.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker SAT-25653 0 None None None 2024-09-05 18:13:28 UTC

Description Pedro Sampaio 2024-04-12 17:39:37 UTC
In puppet-candlepin shipped with the foreman-installer rpm, when calling /usr/share/candlepin/cpdb with --password, cpdb calls liquibase.sh (which calls java) and that leaks the password in the process list.


Note You need to log in before you can comment on or make changes to this bug.