CVE-2014-0192Improper Authorization in Foreman

Severity
5.0MEDIUMNVD
EPSS
0.5%
top 34.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 8
Latest updateMay 17

Description

Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof."

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDtheforeman/foreman5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2r38-hrvx-f45r: Foreman 12022-05-17
CVEList
CVE-2014-0192: Foreman 12014-05-08

📋Vendor Advisories

1
Red Hat
Foreman: provisioning templates are world accessible2014-04-25

💬Community

1
Bugzilla
CVE-2014-0192 Foreman: provisioning templates are world accessible2014-04-29
CVE-2014-0192 — Improper Authorization in Foreman | cvebase