Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-4182

Опубликовано: 03 сент. 2013
Источник: redhat
CVSS2: 6.5
EPSS Низкий

Описание

app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 4ruby193-foremanAffected
OpenStack 3 for RHEL 6ruby193-foremanFixedRHSA-2013:119603.09.2013
Red Hat Satellite 6.0foremanFixedRHEA-2014:117510.09.2014

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=990374foreman: app/controllers/api/v1/hosts_controller.rb API privilege escalation

EPSS

Процентиль: 72%
0.00703
Низкий

6.5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.

nvd
больше 12 лет назад

app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.

debian
больше 12 лет назад

app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 doe ...

github
больше 3 лет назад

app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.

EPSS

Процентиль: 72%
0.00703
Низкий

6.5 Medium

CVSS2