CVE-2020-10710: Theforeman Foreman

Medium severity, CVSS 4.4. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges, such as root, to retrieve the Candlepin plaintext password.

Affected products

  • Theforeman Foreman: before 1.24.1.22 (fixed in 1.24.1.22)

Published 2022-08-16. Last modified 2026-06-17.