CVE-2017-2672
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.
- Affected products
- Foreman
- Theforeman Foreman
- < 1.15
- Fix
- Available
- CVSS 3.0
- 8.8 HIGH
- EPSS
- 1.2% (66th percentile)
- Weakness
- CWE-312, CWE-269
- NVD status
- Modified
- Published
- 2018-06-21
CVE-2017-2672 at NVD
No indexed exploits for CVE-2017-2672 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2017-2672 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.