It was discovered that in Foreman API it's possible to retrieve any organization information, if the organization is not explicitely set in the API request. The fix should make sure that if user does not specify an org explicitly - he's scoped to his orgs only. Initially reported in Foreman public mailing list: https://groups.google.com/forum/#!topic/foreman-users/qAGZh5n6n6M
Upstream bug report: http://projects.theforeman.org/issues/9947
Pull request: https://github.com/theforeman/foreman/pull/2273
This issue has been addressed in the following products: Red Hat Satellite 6.1 Via RHSA-2015:1591 https://access.redhat.com/errata/RHSA-2015:1591
This issue has been addressed in the following products: Red Hat Satellite 6.1 Via RHSA-2015:1592 https://access.redhat.com/errata/RHSA-2015:1592