Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1844

Опубликовано: 29 мар. 2015
Источник: redhat
CVSS2: 4
EPSS Низкий

Описание

Foreman before 1.7.5 allows remote authenticated users to bypass organization and location restrictions by connecting through the REST API.

A flaw was found in the way foreman authorized user actions on resources via the API when an organization was not explicitly set. A remote attacker could use this flaw to obtain additional information about resources they were not authorized to access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenStack ForemanforemanWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) InstallerforemanWill not fix
Red Hat OpenStack Platform 4foremanWill not fix
Red Hat Satellite 6.1aopallianceFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1apache-commons-codec-eap6FixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1apache-mime4jFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1atinjectFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1bouncycastleFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1c3p0FixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1candlepinFixedRHSA-2015:159212.08.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862->CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=1207589foreman: API not scoping resources to taxonomies

EPSS

Процентиль: 49%
0.00261
Низкий

4 Medium

CVSS2

Связанные уязвимости

nvd
больше 10 лет назад

Foreman before 1.7.5 allows remote authenticated users to bypass organization and location restrictions by connecting through the REST API.

debian
больше 10 лет назад

Foreman before 1.7.5 allows remote authenticated users to bypass organ ...

github
больше 3 лет назад

Foreman before 1.7.5 allows remote authenticated users to bypass organization and location restrictions by connecting through the REST API.

EPSS

Процентиль: 49%
0.00261
Низкий

4 Medium

CVSS2

Уязвимость CVE-2015-1844