Bug 1386244 (CVE-2016-7078)

Summary: CVE-2016-7078 foreman: Information leak through organizations and locations feature
Product: [Other] Security Response Reporter: Andrej Nemec <anemec>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: apevec, bkearney, cbillett, ceph-eng-bugs, chrisw, cvsbot-xmlrpc, jjoyce, jmatthew, jschluet, lhh, lpeer, markmc, mburns, mmccune, ohadlevy, rbryant, satellite6-bugs, sclewis, sisharma, srevivo, tdecacqu, tlestach, tsanders
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: foreman 1.15.0 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-21 00:55:30 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1391135, 1391136, 1399322    
Bug Blocks: 1385778, 1432306    

Description Andrej Nemec 2016-10-18 13:28:45 UTC
When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion.

Upstream bug:

http://projects.theforeman.org/issues/16982

Comment 1 Andrej Nemec 2016-10-18 13:29:08 UTC
Acknowledgments:

Name: the Foreman project
Upstream: Daniel Lobato Garcia