Back

HIGH

foreman: models with a 'belongs_to' association to an Organization do not verify association belongs to that Organization

Published Aug 1, 2019

Description

It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 1, 2019
Updated Aug 6, 2024
Reserved Oct 10, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 14, 2017