HIGH
foreman: app/controllers/api/v1/hosts_controller.rb API privilege escalation
Published Sep 16, 2013
7.5
HIGHCVSS 2.0
EPSS 2.40%
Description
app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.
Affected products
No data.
Configuration 2
OR
- ≤ 1.2.1
- 1.2.0
- 1.2.0
- 1.2.0
No data.
OpenStack 3 for RHEL 6
ruby193-foreman-0:1.1.10014-1.2.el6ost
Fixed · RHSA-2013:1196
Red Hat Satellite 6.0
foreman-0:1.6.0.44-1.el6sat
Fixed · RHEA-2014:1175
Red Hat OpenStack Platform 4
ruby193-foreman
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 3 for RHEL 6 | ruby193-foreman-0:1.1.10014-1.2.el6ost | Fixed | RHSA-2013:1196 |
| Red Hat Satellite 6.0 | foreman-0:1.6.0.44-1.el6sat | Fixed | RHEA-2014:1175 |
| Red Hat OpenStack Platform 4 | ruby193-foreman | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- http://projects.theforeman.org/issues/2863 x_refsource_CONFIRMPatch
- http://rhn.redhat.com/errata/RHSA-2013-1196.html vendor-advisoryx_refsource_REDHAT
- http://theforeman.org/manuals/1.2/index.html#Releasenotesfor1.2.2 x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2013-4182 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=990374 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-4182
- https://www.cve.org/CVERecord?id=CVE-2013-4182
| Link | Providers | Tags |
|---|---|---|
| http://projects.theforeman.org/issues/2863 | x_refsource_CONFIRMPatch | |
| http://rhn.redhat.com/errata/RHSA-2013-1196.html | vendor-advisoryx_refsource_REDHAT | |
| http://theforeman.org/manuals/1.2/index.html#Releasenotesfor1.2.2 | x_refsource_CONFIRM | |
| https://access.redhat.com/security/cve/CVE-2013-4182 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=990374 | x_refsource_CONFIRMIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-4182 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-4182 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 16, 2013
Updated Aug 6, 2024
Reserved Jun 12, 2013
Link CVE-2013-4182
CISA Vulnrichment
Updated n/a