CVE-2019-14825
Katello cleartext password storage issue
2.7
LOW
CVSS 3.1
EPSS 0.65%
Description
A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.2. Registry credentials used during container image discovery were inadvertently logged without being masked. This flaw could expose the registry credentials to other privileged users.
How to fix CVE-2019-14825
To remediate CVE-2019-14825, upgrade the affected package to a fixed version below.
- —upgrade to 3.12.2 or later
Is CVE-2019-14825 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 3.0.0.0, < 3.12.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | LOW2.7 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |