Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2100

Опубликовано: 13 фев. 2015
Источник: redhat
CVSS2: 5.5
EPSS Низкий

Описание

Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission.

It was found that access to private bookmarks of users is not properly restricted in Foreman. This could allow an attacker to view the search terms used in these bookmarks which should be private.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenStack ForemanforemanUnder investigation
Red Hat Ceph Storage 1.3foremanUnder investigation
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) InstallerforemanUnder investigation
Red Hat Satellite 6.2 for RHEL 6createrepo_cFixedRHBA-2016:150027.07.2016
Red Hat Satellite 6.2 for RHEL 6facterFixedRHBA-2016:150027.07.2016
Red Hat Satellite 6.2 for RHEL 6gperftoolsFixedRHBA-2016:150027.07.2016
Red Hat Satellite 6.2 for RHEL 6hieraFixedRHBA-2016:150027.07.2016
Red Hat Satellite 6.2 for RHEL 6ipxeFixedRHBA-2016:150027.07.2016
Red Hat Satellite 6.2 for RHEL 6liquibaseFixedRHBA-2016:150027.07.2016
Red Hat Satellite 6.2 for RHEL 6livecd-toolsFixedRHBA-2016:150027.07.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1310675foreman: Unprivileged user can access private bookmarks of other users

EPSS

Процентиль: 42%
0.00201
Низкий

5.5 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.4
nvd
больше 9 лет назад

Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission.

CVSS3: 5.4
debian
больше 9 лет назад

Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authen ...

CVSS3: 5.4
github
больше 3 лет назад

Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission.

EPSS

Процентиль: 42%
0.00201
Низкий

5.5 Medium

CVSS2

Уязвимость CVE-2016-2100