Medium severity4.9NVD Advisory· Published Apr 9, 2019· Updated Jun 17, 2026
CVE-2019-3893
CVE-2019-3893
Description
In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user with the "delete_compute_resource" permission can use this flaw to take control over compute resources managed by foreman. Versions before 1.20.3, 1.21.1, 1.22.0 are vulnerable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*range: >=1.20.0,<1.20.3
- (no CPE)range: <1.20.3, <1.21.1, <1.22.0
- (no CPE)range: 1.20.3
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2019/04/14/2nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/107846nvdThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- github.com/theforeman/foreman/pull/6621nvdThird Party Advisory
- projects.theforeman.org/issues/26450nvdVendor Advisory
News mentions
0No linked articles in our index yet.