SB2016082004 - Security Features in Foreman
Published: August 20, 2016 Updated: August 9, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Security Features (CVE-ID: CVE-2016-4475)
The vulnerability allows a remote authenticated user to execute arbitrary code.
The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass organization and location restrictions and (a) read, (b) edit, or (c) delete arbitrary organizations or locations via unspecified vectors.
Remediation
Install update from vendor's website.