Show plain JSON{"affected_release": [{"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "cfme-0:5.4.0.5-1.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "cfme-gemset-0:5.4.0.5-1.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "cfme-vnc-plugin-0:1.0.0-2.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "libdnet-0:1.12-11.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "lshw-0:B.02.16-4.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "netapp-manageability-sdk-0:4.0P1-3.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "open-vm-tools-0:9.2.3-5.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "prince-0:9.0r2-4.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "pyliblzma-0:0.5.3-7.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-bcrypt-ruby-0:3.0.1-2.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-eventmachine-0:1.0.7-2.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-ffi-0:1.9.8-1.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-io-extra-0:1.2.8-1.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-json-0:1.8.2-2.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-nokogiri-0:1.5.11-2.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-pg-0:0.12.2-9.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-psych-0:2.0.13-1.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-qpid_messaging-0:0.20.2-5.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-therubyracer-0:0.11.0-5.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-thin-0:1.3.1-9.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "sneakernet_ca-0:0.1-2.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "wmi-0:1.3.14-1.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHSA-2021:1313", "cpe": "cpe:/a:redhat:satellite:6.9::el7", "impact": "low", "package": "tfm-rubygem-rest-client-0:2.0.2-3.el7sat", "product_name": "Red Hat Satellite 6.9 for RHEL 7", "release_date": "2021-04-21T00:00:00Z"}, {"advisory": "RHSA-2021:1313", "cpe": "cpe:/a:redhat:satellite_capsule:6.9::el7", "impact": "low", "package": "tfm-rubygem-rest-client-0:2.0.2-3.el7sat", "product_name": "Red Hat Satellite 6.9 for RHEL 7", "release_date": "2021-04-21T00:00:00Z"}], "bugzilla": {"description": "rubygem-rest-client: unsanitized application logging", "id": "1240982", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1240982"}, "csaw": false, "cvss": {"cvss_base_score": "2.1", "cvss_scoring_vector": "AV:L/AC:L/Au:N/C:P/I:N/A:N", "status": "verified"}, "cwe": "CWE-532", "details": ["REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log."], "mitigation": {"lang": "en:us", "value": "The permissions on log files can be changed, e.g. using \"chmod o-rwx\" to prevent anyone but the user and group owner of the file from reading it. Additionally the group permissions can also be removed, e.g. \"chmod g-rwx\" if only the user owning the file should be able to see it."}, "name": "CVE-2015-3448", "package_state": [{"cpe": "cpe:/a:redhat:openstack-installer:5", "fix_state": "Affected", "package_name": "ruby193-rubygem-rest-client", "product_name": "OpenStack Foreman"}, {"cpe": "cpe:/a:redhat:openstack-installer:5", "fix_state": "Affected", "package_name": "rubygem-rest-client", "product_name": "OpenStack Foreman"}, {"cpe": "cpe:/a:redhat:openstack-installer:6", "fix_state": "Affected", "package_name": "ruby193-rubygem-rest-client", "product_name": "Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer"}, {"cpe": "cpe:/a:redhat:openstack-installer:6", "fix_state": "Affected", "package_name": "rubygem-rest-client", "product_name": "Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer"}, {"cpe": "cpe:/a:redhat:enterprise_mrg:2", "fix_state": "Affected", "package_name": "rubygem-rest-client", "product_name": "Red Hat Enterprise MRG 2"}, {"cpe": "cpe:/a:redhat:openshift:2", "fix_state": "Affected", "package_name": "ruby193-rubygem-rest-client", "product_name": "Red Hat OpenShift Enterprise 2"}, {"cpe": "cpe:/a:rhel_sam:1", "fix_state": "Affected", "package_name": "ruby193-rubygem-rest-client", "product_name": "Red Hat Subscription Asset Manager"}, {"cpe": "cpe:/a:rhel_sam:1", "fix_state": "Affected", "package_name": "rubygem-rest-client", "product_name": "Red Hat Subscription Asset Manager"}], "public_date": "2015-01-12T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2015-3448\nhttps://nvd.nist.gov/vuln/detail/CVE-2015-3448"], "threat_severity": "Low"}