CVE-2016-7078

foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:theforeman:foreman:1.15.0:*:*:*:*:*:*:*

Information

Published : 2018-09-10 08:29

Updated : 2019-10-09 16:19


NVD link : CVE-2016-7078

Mitre link : CVE-2016-7078


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

theforeman

  • foreman