SB2016052402 - Information disclosure in Foreman



SB2016052402 - Information disclosure in Foreman

Published: May 24, 2016

Security Bulletin ID SB2016052402
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Information disclosure (CVE-ID: CVE-2016-4995)

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The weakness exists due to improper restriction of access to preview provisioning templates. A remote attacker with permissions to preview host templates can access the template preview for any host if they are able to guess the host name, and access potentially sensitive information.


2) Information disclosure (CVE-ID: CVE-2016-4996)

The vulnerability allows a local attacker to obtain potentially sensitive information.

The weakness exists in the discovery-debug due to improper security restrictions. A local attacker with access to the system journal can obtain the root password by reading the system journal, or by clicking Logs on the console.

Remediation

Install update from vendor's website.