foreman before version 1.15.0 is vulnerable to an information leak...
Vulnerability Description
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-7078
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/theforeman/foreman/commit/5f606e11cf39719bf62f8b1f3396861b32387905
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7078
- http://www.securityfocus.com/bid/96385
- https://theforeman.org/security.html#2016-7078
- https://projects.theforeman.org/issues/16982
- https://seclists.org/oss-sec/2017/q1/470
More from Foreman
View All →Affected Vendor
Foreman
View all reports →