Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ffc7-h8x5-mm7h

Опубликовано: 31 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authenticated user with permissions to view and create templates to read any field from Foreman's database. By using specific strings in the loader macros, users can bypass permissions and access sensitive information.

A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authenticated user with permissions to view and create templates to read any field from Foreman's database. By using specific strings in the loader macros, users can bypass permissions and access sensitive information.

EPSS

Процентиль: 30%
0.00109
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.3
redhat
около 1 года назад

A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authenticated user with permissions to view and create templates to read any field from Foreman's database. By using specific strings in the loader macros, users can bypass permissions and access sensitive information.

CVSS3: 6.3
nvd
около 1 года назад

A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authenticated user with permissions to view and create templates to read any field from Foreman's database. By using specific strings in the loader macros, users can bypass permissions and access sensitive information.

CVSS3: 6.3
debian
около 1 года назад

A vulnerability was found in Foreman's loader macros introduced with r ...

EPSS

Процентиль: 30%
0.00109
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-200