Bug 1386244 (CVE-2016-7078) - CVE-2016-7078 foreman: Information leak through organizations and locations feature
Summary: CVE-2016-7078 foreman: Information leak through organizations and locations f...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2016-7078
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1391135 1391136 1399322
Blocks: 1385778 1432306
TreeView+ depends on / blocked
 
Reported: 2016-10-18 13:28 UTC by Andrej Nemec
Modified: 2021-10-21 00:55 UTC (History)
23 users (show)

Fixed In Version: foreman 1.15.0
Clone Of:
Environment:
Last Closed: 2021-10-21 00:55:30 UTC
Embargoed:


Attachments (Terms of Use)

Description Andrej Nemec 2016-10-18 13:28:45 UTC
When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion.

Upstream bug:

http://projects.theforeman.org/issues/16982

Comment 1 Andrej Nemec 2016-10-18 13:29:08 UTC
Acknowledgments:

Name: the Foreman project
Upstream: Daniel Lobato Garcia


Note You need to log in before you can comment on or make changes to this bug.