V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2020-10716
CVE
Medium

A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw all…

CVSS
4.3
Medium
EPSS
0.01
p50
Published
2020-01-01
Updated
2020-01-01
Description

A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a malicious Satellite user to scan through the Job Invocation, with the ability to search for passwords and other sensitive data. This flaw affects tfm-rubygem-foreman_ansible versions before 4.0.3.4.

Tags · CWE
CWE-285
CAPEC-1
CAPEC-5
CAPEC-13
CAPEC-17
CAPEC-39
CAPEC-45
CAPEC-51
CAPEC-59
CAPEC-60
CAPEC-76
CAPEC-77
CAPEC-87
CAPEC-104
CAPEC-127
CAPEC-402
CAPEC-647
CAPEC-668
Affected products
Ansible-runnerAnsible-runnerAnsiblerole-foreman_scap_clientAnsiblerole-foreman_scap_clientAnsiblerole-insights-clientAnsiblerole-insights-clientAnsiblerole-satellite-receptor-installerAnsiblerole-satellite-receptor-installerCandlepinCandlepinCreaterepo_cCreaterepo_cForemanForemanForeman-bootloaders-redhatForeman-bootloaders-redhatForeman-discovery-imageForeman-discovery-imageForeman-installerForeman-installer
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Timeline
2020-01-01
Published
2020-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.008 · p50
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-647 · CWE-285
└ via CAPEC-647 · CWE-285
└ via CAPEC-127 · CWE-285
└ via CAPEC-60 · CWE-285
└ via CAPEC-60 · CWE-285
└ via CAPEC-647 · CWE-285
└ via CAPEC-668 · CWE-285
└ via CAPEC-13 · CWE-285
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
ansible-runnerTracked
ansible-runnerTracked
ansiblerole-foreman_scap_clientTracked
ansiblerole-foreman_scap_clientTracked
ansiblerole-insights-clientTracked
ansiblerole-insights-clientTracked
ansiblerole-satellite-receptor-installerTracked
ansiblerole-satellite-receptor-installerTracked
candlepinTracked
candlepinTracked
createrepo_cTracked
createrepo_cTracked
foremanTracked
foremanTracked
foreman-bootloaders-redhatTracked
foreman-bootloaders-redhatTracked
foreman-discovery-imageTracked
foreman-discovery-imageTracked
foreman-installerTracked
foreman-installerTracked
Showing first 20 of 783
Source databases
CVE
RED
Related vulnerabilities