Back

MEDIUM

foreman: Access to API routes beneath hosts is not filtered for users with view_host permission

Published Aug 19, 2016

Description

Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitive network interface information via a request to API routes beneath "hosts," as demonstrated by a GET request to api/v2/hosts/secrethost/interfaces.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 19, 2016
Updated Aug 6, 2024
Reserved Jun 10, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jul 12, 2016