The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission, and cannot be shown users, but the environment is still exposed by systemd to non-privileged users.
CVE ID: CVE-2024-22037
CVSS Base Severity: MEDIUM
CVSS Base Score: 5.5
Vendor: SUSE
Product: SUSE Manager Server 5.0
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.44% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)