VYPR
Medium severity4.9NVD Advisory· Published Apr 9, 2019· Updated Jun 17, 2026

CVE-2019-3893

CVE-2019-3893

Description

In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user with the "delete_compute_resource" permission can use this flaw to take control over compute resources managed by foreman. Versions before 1.20.3, 1.21.1, 1.22.0 are vulnerable.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:*
  • cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*range: >=1.20.0,<1.20.3
    • (no CPE)range: <1.20.3, <1.21.1, <1.22.0
    • (no CPE)range: 1.20.3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.