VulnerabilityModified
CVE-2015-1844
Foreman before 1.7.5 allows remote authenticated users to bypass organization and location restrictions by connecting through the REST API.
MEDIUM 4.0EPSS 1.93%
Does this matter?
Lower severity and a low EPSS score (1.93%). Track it; it rarely justifies an emergency change on its own.
Description
Foreman before 1.7.5 allows remote authenticated users to bypass organization and location restrictions by connecting through the REST API.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.93% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- theforeman/foreman
- Source
- secalert@redhat.com
References
- http://projects.theforeman.org/issues/9947Vendor Advisory
- https://access.redhat.com/errata/RHSA-2015:1591
- https://access.redhat.com/errata/RHSA-2015:1592
- https://github.com/theforeman/foreman/pull/2273Patch
- https://groups.google.com/forum/#%21topic/foreman-announce/37KYWhIk4FY
- https://groups.google.com/forum/#%21topic/foreman-users/qAGZh5n6n6M
- http://projects.theforeman.org/issues/9947Vendor Advisory
- https://access.redhat.com/errata/RHSA-2015:1591
- https://access.redhat.com/errata/RHSA-2015:1592
- https://github.com/theforeman/foreman/pull/2273Patch
- https://groups.google.com/forum/#%21topic/foreman-announce/37KYWhIk4FY
- https://groups.google.com/forum/#%21topic/foreman-users/qAGZh5n6n6M
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.