CVE-2022-1662
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In convert2rhel, there's an ansible playbook named ansible/run-convert2rhel.yml which passes the Red Hat Subscription Manager user password via the CLI to convert2rhel. This could allow unauthorized local users to view the password via the process list while convert2rhel is running. However, this ansible playbook is only an example in the upstream repository and it is not shipped in officially supported versions of convert2rhel.
En convert2rhel, se presenta un ansible playbook llamado ansible/run-convert2rhel.yml que pasa la contraseña del usuario de Red Hat Subscription Manager por medio de la CLI a convert2rhel. Esto podría permitir a usuarios locales no autorizados visualizar la contraseña por medio de la lista de procesos mientras convert2rhel esta siendo ejecutando. Sin embargo, este ansible playbook es sólo un ejemplo en el repositorio upstream y no está incluido en las versiones oficialmente soportadas de convert2rhel
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-10 CVE Reserved
- 2022-07-14 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2083851 | 2022-07-20 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Convert2rhel Project Search vendor "Convert2rhel Project" | Convert2rhel Search vendor "Convert2rhel Project" for product "Convert2rhel" | 0.24 Search vendor "Convert2rhel Project" for product "Convert2rhel" and version "0.24" | - |
Affected
| ||||||
Convert2rhel Project Search vendor "Convert2rhel Project" | Convert2rhel Search vendor "Convert2rhel Project" for product "Convert2rhel" | 0.25 Search vendor "Convert2rhel Project" for product "Convert2rhel" and version "0.25" | - |
Affected
|