Privilege escalation in Foreman - CVE-2016-4451
Published: February 27, 2018
Vulnerability identifier: #VU10746
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4451
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to bypass security restrictions.
The weakness exists due to improper enforcement of access controls on certain resources. A remote attacker can bypass organization and location restrictions and read or modify data for an arbitrary organization by leveraging knowledge of the id of that organization.
Affected software
Foreman
Red Hat Satellite
Red Hat Satellite
How to mitigate CVE-2016-4451
Update to versions 1.11.3 or 1.12.0-RC1.