{"api_version":"1","generated_at":"2026-07-23T20:47:18+00:00","cve":"CVE-2016-7078","urls":{"html":"https://cve.report/CVE-2016-7078","api":"https://cve.report/api/cve/CVE-2016-7078.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-7078","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-7078"},"summary":{"title":"CVE-2016-7078","description":"foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2018-09-10 15:29:00","updated_at":"2023-11-07 02:34:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://seclists.org/oss-sec/2017/q1/470","name":"[oss-security] 20170222 CVE-2016-7078: Foreman organization/location authorization vulnerability","refsource":"MLIST","tags":["Mailing List","Third Party Advisory"],"title":"oss-sec: CVE-2016-7078: Foreman organization/location authorization vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/96385","name":"96385","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Foreman CVE-2016-7078 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://theforeman.org/security.html#2016-7078","name":"https://theforeman.org/security.html#2016-7078","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Foreman :: Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://projects.theforeman.org/issues/16982","name":"https://projects.theforeman.org/issues/16982","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Bug #16982: CVE-2016-7078 - User with no organizations or locations can see all resources - Foreman","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/theforeman/foreman/commit/5f606e11cf39719bf62f8b1f3396861b32387905","name":"https://github.com/theforeman/foreman/commit/5f606e11cf39719bf62f8b1f3396861b32387905","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"Fixes #16982 - Scope properly when no taxonomies are set · theforeman/foreman@5f606e1 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7078","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7078","refsource":"CONFIRM","tags":["Issue Tracking","Third Party Advisory"],"title":"1386244 – (CVE-2016-7078) CVE-2016-7078 foreman: Information leak through organizations and locations feature","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-7078","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-7078","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"7078","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"theforeman","cpe5":"foreman","cpe6":"1.15.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"7078","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"theforeman","cpe5":"foreman","cpe6":"1.15.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2016-7078","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"foreman","version":{"version_data":[{"version_value":"1.15.0"}]}}]},"vendor_name":"Foreman"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion."}]},"impact":{"cvss":[[{"vectorString":"4.3/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.0"}],[{"vectorString":"3.5/AV:N/AC:M/Au:S/C:P/I:N/A:N","version":"2.0"}]]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-285"}]}]},"references":{"reference_data":[{"name":"https://github.com/theforeman/foreman/commit/5f606e11cf39719bf62f8b1f3396861b32387905","refsource":"CONFIRM","url":"https://github.com/theforeman/foreman/commit/5f606e11cf39719bf62f8b1f3396861b32387905"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7078","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7078"},{"name":"96385","refsource":"BID","url":"http://www.securityfocus.com/bid/96385"},{"name":"https://theforeman.org/security.html#2016-7078","refsource":"CONFIRM","url":"https://theforeman.org/security.html#2016-7078"},{"name":"https://projects.theforeman.org/issues/16982","refsource":"CONFIRM","url":"https://projects.theforeman.org/issues/16982"},{"name":"[oss-security] 20170222 CVE-2016-7078: Foreman organization/location authorization vulnerability","refsource":"MLIST","url":"https://seclists.org/oss-sec/2017/q1/470"}]}},"nvd":{"publishedDate":"2018-09-10 15:29:00","lastModifiedDate":"2023-11-07 02:34:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:theforeman:foreman:1.15.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"7078","Ordinal":"93384","Title":"CVE-2016-7078","CVE":"CVE-2016-7078","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"7078","Ordinal":"1","NoteData":"foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"7078","Ordinal":"2","NoteData":"2018-09-10","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"7078","Ordinal":"3","NoteData":"2018-09-11","Type":"Other","Title":"Modified"}]}}}