Back

LOW

Foreman: disclosure of executed commands and outputs in foreman / red hat satellite

Published Mar 15, 2025

Description

A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 15, 2025
Updated Nov 21, 2025
Reserved Mar 10, 2025
CISA Vulnrichment
Updated Mar 17, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 13, 2025