Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitive network interface information via a request to API routes beneath "hosts," as demonstrated by a GET request to api/v2/hosts/secrethost/interfaces.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2016-08-19T21:00:00

Updated: 2024-08-06T01:00:59.857Z

Reserved: 2016-06-10T00:00:00

Link: CVE-2016-5390

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2016-08-19T21:59:11.387

Modified: 2019-03-08T17:02:03.027

Link: CVE-2016-5390

cve-icon Redhat

Severity : Low

Publid Date: 2016-07-12T00:00:00Z

Links: CVE-2016-5390 - Bugzilla