CVE-2016-7078
low-risk
Published 2018-09-10
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion.
Do I need to act?
-
0.32% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
4
CVSS 4.3/10
Medium
NETWORK
/ LOW complexity
Affected Products (1)
Affected Vendors
References (12)
Third Party Advisory
http://www.securityfocus.com/bid/96385
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7078
Third Party Advisory
https://github.com/theforeman/foreman/commit/5f606e11cf39719bf62f8b1f3396861b323...
Vendor Advisory
https://projects.theforeman.org/issues/16982
Mailing List
https://seclists.org/oss-sec/2017/q1/470
Vendor Advisory
https://theforeman.org/security.html#2016-7078
Third Party Advisory
http://www.securityfocus.com/bid/96385
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7078
Third Party Advisory
https://github.com/theforeman/foreman/commit/5f606e11cf39719bf62f8b1f3396861b323...
Vendor Advisory
https://projects.theforeman.org/issues/16982
Mailing List
https://seclists.org/oss-sec/2017/q1/470
Vendor Advisory
https://theforeman.org/security.html#2016-7078
24
/ 100
low-risk
Severity
18/34 · Moderate
Exploitability
1/34 · Minimal
Exposure
5/34 · Minimal