CVE-2015-1844Missing Authorization in Foreman

Severity
4.0MEDIUMNVD
EPSS
0.3%
top 50.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 14
Latest updateMay 14

Description

Foreman before 1.7.5 allows remote authenticated users to bypass organization and location restrictions by connecting through the REST API.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r6gp-x66j-mhw7: Foreman before 12022-05-14
CVEList
CVE-2015-1844: Foreman before 12015-08-14

📋Vendor Advisories

1
Red Hat
foreman: API not scoping resources to taxonomies2015-03-29

💬Community

16
Bugzilla
CVE-2015-8934 libarchive: out of bounds heap read in RAR parser2016-06-23
Bugzilla
CVE-2015-8930 libarchive: Endless loop in ISO parser2016-06-23
Bugzilla
CVE-2015-8923 libarchive: Unclear crashes in ZIP parser2016-06-22
Bugzilla
CVE-2015-8931 libarchive: Undefined behavior (signed integer overflow) in mtree parser2016-06-22
Bugzilla
CVE-2015-8922 libarchive: NULL pointer access in 7z parser2016-06-21
CVE-2015-1844 — Missing Authorization in Foreman | cvebase