SB2022083131 - Information disclosure in Convert2RHEL 6
Published: August 31, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2022-0851)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to the activation key is subsequently passed to subscription-manager via the command line when the --activationkey option is used with convert2rhel. A local user can view the list of running processes on the system and obtain the activation key.
Remediation
Install update from vendor's website.