CVE-2016-7078

foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion.
Configurations

Configuration 1 (hide)

cpe:2.3:a:theforeman:foreman:1.15.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:57

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/96385 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/96385 - Third Party Advisory, VDB Entry
References () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7078 - Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7078 - Issue Tracking, Third Party Advisory
References () https://github.com/theforeman/foreman/commit/5f606e11cf39719bf62f8b1f3396861b32387905 - Third Party Advisory () https://github.com/theforeman/foreman/commit/5f606e11cf39719bf62f8b1f3396861b32387905 - Third Party Advisory
References () https://projects.theforeman.org/issues/16982 - Vendor Advisory () https://projects.theforeman.org/issues/16982 - Vendor Advisory
References () https://seclists.org/oss-sec/2017/q1/470 - Mailing List, Third Party Advisory () https://seclists.org/oss-sec/2017/q1/470 - Mailing List, Third Party Advisory
References () https://theforeman.org/security.html#2016-7078 - Vendor Advisory () https://theforeman.org/security.html#2016-7078 - Vendor Advisory

Information

Published : 2018-09-10 15:29

Updated : 2024-11-21 02:57


NVD link : CVE-2016-7078

Mitre link : CVE-2016-7078

CVE.ORG link : CVE-2016-7078


JSON object : View

Products Affected

theforeman

  • foreman
CWE
CWE-285

Improper Authorization

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor