SB2016052402 - Information disclosure in Foreman
Published: May 24, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2016-4995)
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The weakness exists due to improper restriction of access to preview provisioning templates. A remote attacker with permissions to preview host templates can access the template preview for any host if they are able to guess the host name, and access potentially sensitive information.
2) Information disclosure (CVE-ID: CVE-2016-4996)
The vulnerability allows a local attacker to obtain potentially sensitive information.The weakness exists in the discovery-debug due to improper security restrictions. A local attacker with access to the system journal can obtain the root password by reading the system journal, or by clicking Logs on the console.
Remediation
Install update from vendor's website.