foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.
Project Subscriptions
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-7957 | foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T01:50:47.449Z
Reserved: 2016-08-23T00:00:00
Link: CVE-2016-7077
No data.
Status : Modified
Published: 2018-09-10T15:29:01.107
Modified: 2024-11-21T02:57:24.807
Link: CVE-2016-7077
OpenCVE Enrichment
No data.
EUVD