SB2016050203 - Privilege escalation in Foreman
Published: May 2, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Privilege escalation (CVE-ID: CVE-2016-4451)
The vulnerability allows a remote authenticated attacker to bypass security restrictions.
The weakness exists due to improper enforcement of access controls on certain resources. A remote attacker can bypass organization and location restrictions and read or modify data for an arbitrary organization by leveraging knowledge of the id of that organization.
Remediation
Install update from vendor's website.