CVE-2016-5390Sensitive Information Exposure in Foreman

Severity
5.3MEDIUMNVD
EPSS
0.3%
top 50.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 19
Latest updateMay 14

Description

Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitive network interface information via a request to API routes beneath "hosts," as demonstrated by a GET request to api/v2/hosts/secrethost/interfaces.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages1 packages

NVDtheforeman/foreman1.11.01.11.4+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gh7p-2f9h-jrgc: Foreman before 12022-05-14
CVEList
CVE-2016-5390: Foreman before 12016-08-19

📋Vendor Advisories

1
Red Hat
foreman: Access to API routes beneath hosts is not filtered for users with view_host permission2016-07-12

💬Community

1
Bugzilla
CVE-2016-5390 foreman: Access to API routes beneath hosts is not filtered for users with view_host permission2016-07-12
CVE-2016-5390 — Sensitive Information Exposure | cvebase