Fedora Account System
Red Hat Associate
Red Hat Customer
It was found that an authenticated user can leverage the SELECT query condition to extract information regarding existence of various values in the database. Upstream bug: http://projects.theforeman.org/issues/23028
Acknowledgments: Name: Martin Povolny (Red Hat)
Upstream Patch: https://github.com/theforeman/foreman/pull/5363
Upstream Patch: http://projects.theforeman.org/projects/foreman/repository/revisions/274665e24373de670a9107d4565c10ec41dd5f65
This issue has been addressed in the following products: Red Hat Satellite 6.4 for RHEL 7 Via RHSA-2018:2927 https://access.redhat.com/errata/RHSA-2018:2927