CVE-2016-7077
Summary
| CVE | CVE-2016-7077 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-10 15:29:00 UTC |
| Updated | 2023-11-07 02:34:00 UTC |
| Description | foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Theforeman | Foreman | All | All | All | All |
| Application | Theforeman | Foreman | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Foreman CVE-2016-7077 Local Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Foreman :: Security | CONFIRM | theforeman.org | Vendor Advisory |
| Bug #16971: CVE-2016-7077 - Association lists (for < 6 items) shown without authorization/filters - Foreman | CONFIRM | projects.theforeman.org | Exploit, Vendor Advisory |
| 1385777 – (CVE-2016-7077) CVE-2016-7077 foreman: Foreman information leak through unauthorized multiple_checkboxes helper | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.