Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6632 | A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively. |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 17 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 15 Mar 2025 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | foreman: Disclosure of Executed Commands and Outputs in Foreman / Red Hat Satellite | Foreman: disclosure of executed commands and outputs in foreman / red hat satellite |
| First Time appeared |
Redhat
Redhat satellite |
|
| CPEs | cpe:/a:redhat:satellite:6 | |
| Vendors & Products |
Redhat
Redhat satellite |
|
| References |
|
Fri, 14 Mar 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively. | |
| Title | foreman: Disclosure of Executed Commands and Outputs in Foreman / Red Hat Satellite | |
| Weaknesses | CWE-922 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-21T07:08:05.036Z
Reserved: 2025-03-10T12:20:21.761Z
Link: CVE-2025-2157
Updated: 2025-03-17T16:53:10.618Z
Status : Deferred
Published: 2025-03-15T07:15:34.930
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-2157
OpenCVE Enrichment
No data.
EUVD