Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2022-2806 |
CWE-ID | CWE-532 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software Subscribe |
sos Server applications / Other server solutions |
Vendor | sosreport |
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU67131
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-2806
CWE-ID:
CWE-532 - Information Exposure Through Log Files
Exploit availability: No
DescriptionThe vulnerability allows a local user to gain access to sensitive information.
The
vulnerability exists due to the application does not apply encryption
or obfuscation for the RHV admin password. An attacker with access to
the application can gain access to sensitive information.
Install updates from vendor's website.
Vulnerable software versionssos: 0.6 - 4.3
http://github.com/sosreport/sos/pull/2947
http://bugzilla.redhat.com/show_bug.cgi?id=2080005
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?