CVE-2016-2100
MEDIUMForeman < 1.10.2 - Improper Access Control
Title source: ruleDescription
Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission.
Scores
CVSS v3
5.4
EPSS
0.0020
EPSS Percentile
42.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Classification
CWE
CWE-284
Status
draft
Affected Products (3)
theforeman/foreman
< 1.10.2
theforeman/foreman
theforeman/foreman
Timeline
Published
May 20, 2016
Tracked Since
Feb 18, 2026