CVE-2015-5233Improper Access Control in Foreman

Severity
4.2MEDIUMNVD
EPSS
0.2%
top 58.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 11
Latest updateMay 17

Description

Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary hosts or (2) remote authenticated users with the destroy_reports permission to delete reports from arbitrary hosts via direct access to the (a) individual report show/delete pages or (b) APIs.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 1.6 | Impact: 2.5

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m3c3-hv22-w332: Foreman before 12022-05-17
CVEList
CVE-2015-5233: Foreman before 12016-04-11

📋Vendor Advisories

1
Red Hat
foreman: reports show/destroy not restricted by host authorization2015-08-27

💬Community

1
Bugzilla
CVE-2015-5233 foreman: reports show/destroy not restricted by host authorization2015-09-11
CVE-2015-5233 — Improper Access Control in Foreman | cvebase