foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://theforeman.org/security.html#2016-7077 | vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7077 | third party advisory issue tracking |
http://www.securityfocus.com/bid/94230 | third party advisory vdb entry |
https://projects.theforeman.org/issues/16971 | vendor advisory exploit |