Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1386244 - (CVE-2016-7078) CVE-2016-7078 foreman: Information leak through organizations and locations feature
CVE-2016-7078 foreman: Information leak through organizations and locations f...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20161018,reported=2...
: Security
Depends On: 1391135 1391136 1399322
Blocks: 1385778 1432306
  Show dependency treegraph
 
Reported: 2016-10-18 09:28 EDT by Andrej Nemec
Modified: 2018-09-10 09:35 EDT (History)
27 users (show)

See Also:
Fixed In Version: foreman 1.15.0
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Andrej Nemec 2016-10-18 09:28:45 EDT
When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion.

Upstream bug:

http://projects.theforeman.org/issues/16982
Comment 1 Andrej Nemec 2016-10-18 09:29:08 EDT
Acknowledgments:

Name: the Foreman project
Upstream: Daniel Lobato Garcia

Note You need to log in before you can comment on or make changes to this bug.