CVE-2019-3893
Last modified
CVE-2019-3893 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user with the "delete_compute_resource" permission can use this flaw to take control over compute resources managed by foreman. EPSS estimates a 1.86% chance of exploitation in the next 30 days.
Description
In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user with the "delete_compute_resource" permission can use this flaw to take control over compute resources managed by foreman. Versions before 1.20.3, 1.21.1, 1.22.0 are vulnerable.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Theforeman | Foreman | >= 1.20.0, < 1.20.3 |
| Theforeman | Foreman | >= 1.21.0, < 1.21.1 |
| Redhat | Satellite | 6.0 |
References
- http://www.openwall.com/lists/oss-security/2019/04/14/2Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/107846Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3893Issue Tracking, Third Party Advisory
- https://github.com/theforeman/foreman/pull/6621Third Party Advisory
- https://projects.theforeman.org/issues/26450Vendor Advisory
- http://www.openwall.com/lists/oss-security/2019/04/14/2Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/107846Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3893Issue Tracking, Third Party Advisory
- https://github.com/theforeman/foreman/pull/6621Third Party Advisory
- https://projects.theforeman.org/issues/26450Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3893?
How severe is CVE-2019-3893?
How do I fix CVE-2019-3893?
Are you affected by CVE-2019-3893?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
