foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/94230 | Third Party Advisory VDB Entry |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7077 | Issue Tracking Third Party Advisory |
https://projects.theforeman.org/issues/16971 | Exploit Vendor Advisory |
https://theforeman.org/security.html#2016-7077 | Vendor Advisory |
http://www.securityfocus.com/bid/94230 | Third Party Advisory VDB Entry |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7077 | Issue Tracking Third Party Advisory |
https://projects.theforeman.org/issues/16971 | Exploit Vendor Advisory |
https://theforeman.org/security.html#2016-7077 | Vendor Advisory |
Configurations
History
21 Nov 2024, 02:57
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/94230 - Third Party Advisory, VDB Entry | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7077 - Issue Tracking, Third Party Advisory | |
References | () https://projects.theforeman.org/issues/16971 - Exploit, Vendor Advisory | |
References | () https://theforeman.org/security.html#2016-7077 - Vendor Advisory |
Information
Published : 2018-09-10 15:29
Updated : 2024-11-21 02:57
NVD link : CVE-2016-7077
Mitre link : CVE-2016-7077
CVE.ORG link : CVE-2016-7077
JSON object : View
Products Affected
theforeman
- foreman