CVE-2024-22037 Information

Description

The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission and cannot be shown users but the environment is still exposed by systemd to non-privileged users.

Reference

https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-22037

Share on: