foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/94230 | Third Party Advisory VDB Entry |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7077 | Issue Tracking Third Party Advisory |
https://projects.theforeman.org/issues/16971 | Exploit Vendor Advisory |
https://theforeman.org/security.html#2016-7077 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2018-09-10 15:29
Updated : 2024-02-04 20:03
NVD link : CVE-2016-7077
Mitre link : CVE-2016-7077
CVE.ORG link : CVE-2016-7077
JSON object : View
Products Affected
theforeman
- foreman