Red Hat Satellite Plaintext Candlepin Password Disclosure via satellite-installer
CVE-2020-10710 Published on August 16, 2022

A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges, such as root, to retrieve the Candlepin plaintext password.

NVD

Weakness Type

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.


Products Associated with CVE-2020-10710

stack.watch emails you whenever new vulnerabilities are published in Theforeman Foreman or Red Hat Satellite. Just hit a watch button to start following.

 
 

Exploit Probability

EPSS
0.05%
Percentile
14.40%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.