CVE-2022-1662 describes a vulnerability in convert2rhel where an example Ansible playbook (ansible/run-convert2rhel.yml) could expose the Red Hat Subscription Manager user password via the process list to unauthorized local users. This issue affects the convert2rhel project, but the vulnerable playbook is not included in officially supported versions. The vulnerability has a CVSS score of 5.5 (Medium), indicating a low attack complexity and requiring local access, with a potential impact of high confidentiality compromise. There is no impact on integrity or availability. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.24CPE matchmatch criteria | cpe:2.3:a:convert2rhel_project:convert2rhel:0.24:*:*:*:*:*:*:* | ||
0.25CPE matchmatch criteria | cpe:2.3:a:convert2rhel_project:convert2rhel:0.25:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.