A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 17 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 15 Mar 2025 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | foreman: Disclosure of Executed Commands and Outputs in Foreman / Red Hat Satellite | Foreman: disclosure of executed commands and outputs in foreman / red hat satellite |
| First Time appeared |
Redhat
Redhat satellite |
|
| CPEs | cpe:/a:redhat:satellite:6 | |
| Vendors & Products |
Redhat
Redhat satellite |
|
| References |
|
Fri, 14 Mar 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively. | |
| Title | foreman: Disclosure of Executed Commands and Outputs in Foreman / Red Hat Satellite | |
| Weaknesses | CWE-922 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2025-03-15T06:35:52.221Z
Updated: 2025-09-02T22:07:12.820Z
Reserved: 2025-03-10T12:20:21.761Z
Link: CVE-2025-2157
Updated: 2025-03-17T16:53:10.618Z
Status : Received
Published: 2025-03-15T07:15:34.930
Modified: 2025-03-15T07:15:34.930
Link: CVE-2025-2157