CVE-2025-2157

CVSS 3.1 Score 3.3 of 10 (low)

Details

Published Mar 15, 2025
CWE ID 922

Summary

CVE-2025-2157 is a vulnerability affecting Foreman and Red Hat Satellite. It arises from improper file permissions that permit low-privileged OS users to access sensitive temporary files located in /var/tmp. These files may contain command outputs of significance, including the /etc/shadow file. An attacker could exploit this issue to achieve information disclosure and potentially privilege escalation, posing a threat to system security.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share