CVE-2016-7078
Summary
| CVE | CVE-2016-7078 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-10 15:29:00 UTC |
| Updated | 2023-11-07 02:34:00 UTC |
| Description | foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Theforeman | Foreman | 1.15.0 | All | All | All |
| Application | Theforeman | Foreman | 1.15.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-sec: CVE-2016-7078: Foreman organization/location authorization vulnerability | MLIST | seclists.org | Mailing List, Third Party Advisory |
| Foreman CVE-2016-7078 Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Foreman :: Security | CONFIRM | theforeman.org | Vendor Advisory |
| Bug #16982: CVE-2016-7078 - User with no organizations or locations can see all resources - Foreman | CONFIRM | projects.theforeman.org | Vendor Advisory |
| Fixes #16982 - Scope properly when no taxonomies are set · theforeman/foreman@5f606e1 · GitHub | CONFIRM | github.com | Third Party Advisory |
| 1386244 – (CVE-2016-7078) CVE-2016-7078 foreman: Information leak through organizations and locations feature | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.