Back

HIGH

foreman: inside discovery-debug, the root password is displayed in plaintext

Published Jul 14, 2017

Description

discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local users with access to the system journal to obtain the root password by reading the system journal, or by clicking Logs on the console.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 14, 2017
Updated Aug 6, 2024
Reserved May 24, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 22, 2016