Описание
Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.
Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2016-4995
- https://access.redhat.com/errata/RHSA-2018:0336
- https://access.redhat.com/security/cve/CVE-2016-4995
- https://bugzilla.redhat.com/show_bug.cgi?id=1348939
- https://theforeman.org/security.html#2016-4995
- http://projects.theforeman.org/issues/15490
- http://projects.theforeman.org/projects/foreman/repository/revisions/c3c186de12be15e55d9582e54659f765304a1073
Связанные уязвимости
Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.
Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.
Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restr ...