Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mwjw-3593-mrg6

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.

Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.

EPSS

Процентиль: 53%
0.00298
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
redhat
больше 9 лет назад

Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.

CVSS3: 5.3
nvd
больше 9 лет назад

Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.

CVSS3: 5.3
debian
больше 9 лет назад

Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restr ...

EPSS

Процентиль: 53%
0.00298
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200