A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authenticated user with permissions to view and create templates to read any field from Foreman's database. By using specific strings in the loader macros, users can bypass permissions and access sensitive information.
References
Configurations
No configuration.
History
06 Nov 2024, 09:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary |
|
01 Nov 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
31 Oct 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-31 15:15
Updated : 2024-11-06 09:15
NVD link : CVE-2024-8553
Mitre link : CVE-2024-8553
CVE.ORG link : CVE-2024-8553
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor