In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade RHEL:7
foreman-compute
to version 0:1.20.1.34-1.el7sat or higher.
This issue was patched in RHSA-2019:1222
.
Note: Versions mentioned in the description apply only to the upstream foreman-compute
package and not the foreman-compute
package as distributed by RHEL
.
See How to fix?
for RHEL:7
relevant fixed versions and status.
It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify the database and prevent Satellite from fetching package updates, thus preventing all Satellite hosts from accessing those updates.