VulnerabilityModified
CVE-2016-7077
foreman before 1.14.0 is vulnerable to an information leak.
MEDIUM 4.3EPSS 1.37%
Does this matter?
Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.
Description
foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285, CWE-200
- Affected
- theforeman/foreman
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/94230Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7077Issue Tracking, Third Party Advisory
- https://projects.theforeman.org/issues/16971Exploit, Vendor Advisory
- https://theforeman.org/security.html#2016-7077Vendor Advisory
- http://www.securityfocus.com/bid/94230Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7077Issue Tracking, Third Party Advisory
- https://projects.theforeman.org/issues/16971Exploit, Vendor Advisory
- https://theforeman.org/security.html#2016-7077Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.