The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass organization and location restrictions and (a) read, (b) edit, or (c) delete arbitrary organizations or locations via unspecified vectors.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
https://theforeman.org/security.html#2016-4475 | vendor advisory |
http://projects.theforeman.org/issues/15268 | patch vendor advisory |
https://access.redhat.com/errata/RHBA-2016:1615 | vendor advisory |
http://projects.theforeman.org/projects/foreman/repository/revisions/a30ab44ed6f140f1791afc51a1e448afc2ff28f9 | patch vendor advisory |
http://www.securityfocus.com/bid/92125 | vdb entry third party advisory |