CVE-2024-3716

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/06/2024
Last modified:
18/06/2024

Description

A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the process list and allows an attacker to take advantage and obtain the password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:*