Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mwjw-3593-mrg6

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.

Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.

EPSS

Процентиль: 62%
0.01083
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
redhat
около 10 лет назад

Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.

CVSS3: 5.3
nvd
почти 10 лет назад

Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.

CVSS3: 5.3
debian
почти 10 лет назад

Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restr ...

EPSS

Процентиль: 62%
0.01083
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200