Back

HIGH

foreman: API and UI actions/URLs not limited to the orgs/locations assigned

Published Aug 19, 2016

Description

The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass organization and location restrictions and (a) read, (b) edit, or (c) delete arbitrary organizations or locations via unspecified vectors.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 19, 2016
Updated Aug 6, 2024
Reserved May 2, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 2, 2016