An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through the web UI or API, if they can discover or guess the UUID of the task.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-2219 An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through the web UI or API, if they can discover or guess the UUID of the task.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-04T22:17:19.748Z

Reserved: 2019-03-27T00:00:00

Link: CVE-2019-10198

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-07-31T22:15:12.590

Modified: 2024-11-21T04:18:38.260

Link: CVE-2019-10198

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-07-12T00:00:00Z

Links: CVE-2019-10198 - Bugzilla

cve-icon OpenCVE Enrichment

No data.