VYPR
High severity7.8NVD Advisory· Published Apr 15, 2019· Updated Jun 17, 2026

CVE-2019-3891

CVE-2019-3891

Description

It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify the database and prevent Satellite from fetching package updates, thus preventing all Satellite hosts from accessing those updates.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Red Hat/Satellite2 versions
    cpe:2.3:a:redhat:satellite:6.4:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:redhat:satellite:6.4:*:*:*:*:*:*:*
    • (no CPE)range: 6.4
  • Red Hat/candlepinv5
    Range: affects Satellite 6.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.