LOW
Foreman: disclosure of executed commands and outputs in foreman / red hat satellite
Published Mar 15, 2025
3.3
LOWCVSS 3.1
EPSS 0.15%
Description
A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively.
Affected products
-
-
- Version 6.16StatusaffectedConstraints-
- Version 6.17StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Red Hat | Red Hat Satellite 6 | affected |
| |||||||||
| Red Hat | Satellite Server | n/a |
|
No data.
No data.
Red Hat Satellite 6
foreman
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Satellite 6 | foreman | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://access.redhat.com/security/cve/CVE-2025-2157 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2351092 issue-trackingx_refsource_REDHATIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2025-2157
- https://www.cve.org/CVERecord?id=CVE-2025-2157
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-2157 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2351092 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-2157 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-2157 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 15, 2025
Updated Nov 21, 2025
Reserved Mar 10, 2025
Link CVE-2025-2157
CISA Vulnrichment
Updated Mar 17, 2025