Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-5390

Опубликовано: 19 авг. 2016
Источник: nvd
CVSS3: 5.3
CVSS2: 3.5
EPSS Низкий

Описание

Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitive network interface information via a request to API routes beneath "hosts," as demonstrated by a GET request to api/v2/hosts/secrethost/interfaces.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*
Версия от 1.11.0 (включая) до 1.11.4 (исключая)
cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*
Версия от 1.12.0 (включая) до 1.12.1 (исключая)

EPSS

Процентиль: 68%
0.01309
Низкий

5.3 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.3
redhat
около 10 лет назад

Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitive network interface information via a request to API routes beneath "hosts," as demonstrated by a GET request to api/v2/hosts/secrethost/interfaces.

CVSS3: 5.3
debian
почти 10 лет назад

Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authentica ...

CVSS3: 5.3
github
больше 4 лет назад

Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitive network interface information via a request to API routes beneath "hosts," as demonstrated by a GET request to api/v2/hosts/secrethost/interfaces.

EPSS

Процентиль: 68%
0.01309
Низкий

5.3 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-200