Red Hat Bugzilla – Bug 1385777
CVE-2016-7077 foreman: Foreman information leak through unauthorized multiple_checkboxes helper
Last modified: 2018-09-10 09:29:58 EDT
Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6. Affects Foreman since at least version 1.8. Upstream bug: http://projects.theforeman.org/issues/16971
Acknowledgments: Name: the Foreman project Upstream: Jitendra Yejare