VulnerabilityModified
CVE-2014-0192
Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof."
MEDIUM 5.0EPSS 1.54%
Does this matter?
Lower severity and a low EPSS score (1.54%). Track it; it rarely justifies an emergency change on its own.
Description
Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.54% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- theforeman/foreman
- Source
- secalert@redhat.com
References
- http://projects.theforeman.org/issues/5436Exploit, Vendor Advisory
- http://theforeman.org/security.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1092354Patch
- http://projects.theforeman.org/issues/5436Exploit, Vendor Advisory
- http://theforeman.org/security.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1092354Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.