VYPR
Unrated severityOSV Advisory· Published Jun 21, 2018· Updated Aug 5, 2024

CVE-2017-2672

CVE-2017-2672

Description

A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Foreman versions prior to 1.15 log image registration passwords in plaintext, allowing users with audit log access to compromise provisioned systems.

Vulnerability

A flaw exists in Foreman versions prior to 1.15 (the issue was fixed in Satellite 6.3 [1]) where the password used for provisioning images (e.g., OpenStack images) is recorded in plaintext in the audit log when an image is added or registered [3]. This occurs because the password field is not filtered from the log entry, exposing the credential to anyone with access to the audit log [3].

Exploitation

An attacker needs read access to the Foreman audit log. No special network position or authentication to the compute resource is required directly; the attacker must simply have credentials to view Foreman logs (e.g., a Foreman user with appropriate permissions). The audit log can be viewed through the Foreman web UI or directly on the filesystem. The attacker can then locate log entries related to image registration and extract the plaintext password [3].

Impact

Successful exploitation allows the attacker to obtain the plaintext password for provisioned systems (e.g., newly created virtual machines using the registered image). With this password, the attacker can authenticate to those systems and achieve unauthorized access, potentially leading to information disclosure, data tampering, or further compromise [1][3].

Mitigation

Red Hat Satellite users should apply the update available via RHSA-2018:0336 (Satellite 6.3) [1]. Foreman users should upgrade to version 1.15 or later. There is no workaround for the audit log password leak; users concerned about exposure should restrict access to the audit log until the upgrade is applied. The issue has been fixed; no KEV listing exists.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.