Red Hat Bugzilla – Bug 1355728
CVE-2016-5390 foreman: Access to API routes beneath hosts is not filtered for users with view_host permission
Last modified: 2016-07-12 07:20:50 EDT
It was reported that non-admin users with the view_hosts permission containing a filter are able to access API routes beneath "hosts" such as GET /api/v2/hosts/secrethost/interfaces without the filter being taken into account. This allows users to access network interface details (including BMC login details) for any host. Affects Foreman 1.10.0 and higher. Upstream bug: http://projects.theforeman.org/issues/15653
Acknowledgments: Name: the Foreman project Upstream: Daniel Lobato Garcia, Nacho Barrientos, Steve Traylen