CVE-2016-7078

MEDIUM

Foreman < 1.15.0 - Improper Authorization in Organizations and Locations Feature

Title source: llm
STIX 2.1

Description

foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion.

References (6)

Core 6
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7078
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96385
Vendor Advisory x_refsource_confirm
https://theforeman.org/security.html#2016-7078
Vendor Advisory x_refsource_confirm
https://projects.theforeman.org/issues/16982
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://seclists.org/oss-sec/2017/q1/470

Scores

CVSS v3 4.3
EPSS 0.0136
EPSS Percentile 68.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200 CWE-285
Status published
Products (1)
theforeman/foreman 1.15.0
Published Sep 10, 2018
Tracked Since Feb 18, 2026