Exposure of Sensitive Information to an Unauthorized Actor in foreman_fog_proxmox
High severity
GitHub Reviewed
Published
Jun 10, 2021
to the GitHub Advisory Database
•
Updated Jan 24, 2023
Description
Published by the National Vulnerability Database
Jun 7, 2021
Reviewed
Jun 10, 2021
Published to the GitHub Advisory Database
Jun 10, 2021
Last updated
Jan 24, 2023
A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Versions of foreman_fog_proxmox prior to 0.13.1 are affected.
References