SB2018091018 - Information disclosure in Foreman



SB2018091018 - Information disclosure in Foreman

Published: September 10, 2018 Updated: August 8, 2020

Security Bulletin ID SB2018091018
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2016-7077)

The vulnerability allows a remote authenticated user to gain access to sensitive information.

foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.


Remediation

Install update from vendor's website.