Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2016-7078

Disclosure Date: September 10, 2018 (last updated November 08, 2023)
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion.
0
Attacker Value
Unknown

CVE-2015-5282

Disclosure Date: September 25, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.
0
Attacker Value
Unknown

CVE-2017-7505

Disclosure Date: May 26, 2017 (last updated November 26, 2024)
Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.
0