Insecure Storage of Sensitive Information Affecting foreman-ovirt package, versions *


Severity

Recommended
0.0
low
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.04% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL7-FOREMANOVIRT-9464026
  • published18 Mar 2025
  • disclosed13 Mar 2025

Introduced: 13 Mar 2025

NewCVE-2025-2157  (opens in a new tab)
CWE-922  (opens in a new tab)

How to fix?

There is no fixed version for RHEL:7 foreman-ovirt.

NVD Description

Note: Versions mentioned in the description apply only to the upstream foreman-ovirt package and not the foreman-ovirt package as distributed by RHEL. See How to fix? for RHEL:7 relevant fixed versions and status.

A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively.

CVSS Base Scores

version 3.1