Back

MEDIUM

foreman: Information leak through organizations and locations feature

Published Sep 10, 2018

Description

foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 10, 2018
Updated Aug 6, 2024
Reserved Aug 23, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Oct 18, 2016