Privilege escalation in Foreman - CVE-2016-4451

 

Privilege escalation in Foreman - CVE-2016-4451

Published: February 27, 2018


Vulnerability identifier: #VU10746
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4451
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to bypass security restrictions.

The weakness exists due to improper enforcement of access controls on certain resources. A remote attacker can bypass organization and location restrictions and read or modify data for an arbitrary organization by leveraging knowledge of the id of that organization.


Affected software

Foreman
Red Hat Satellite

How to mitigate CVE-2016-4451

Update to versions 1.11.3 or 1.12.0-RC1.


External References

Related Security Bulletins