CVE-2016-4451Improper Access Control in Foreman

Severity
5.0MEDIUMNVD
EPSS
0.1%
top 65.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 19
Latest updateMay 14

Description

The (1) Organization and (2) Locations APIs in Foreman before 1.11.3 and 1.12.x before 1.12.0-RC1 allow remote authenticated users with unlimited filters to bypass organization and location restrictions and read or modify data for an arbitrary organization by leveraging knowledge of the id of that organization.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 1.6 | Impact: 3.4

Affected Packages1 packages

NVDtheforeman/foreman1.11.2+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jh5m-3mwm-hr2m: The (1) Organization and (2) Locations APIs in Foreman before 12022-05-14
CVEList
CVE-2016-4451: The (1) Organization and (2) Locations APIs in Foreman before 12016-08-19

📋Vendor Advisories

1
Red Hat
foreman: privilege escalation through Organization and Locations API2016-05-25

💬Community

1
Bugzilla
CVE-2016-4451 foreman: privilege escalation through Organization and Locations API2016-05-26
CVE-2016-4451 — Improper Access Control in Foreman | cvebase