CVE-2016-2100

Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission.
Configurations

Configuration 1 (hide)

cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:theforeman:foreman:1.11.0:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.11.0:rc1:*:*:*:*:*:*

History

13 Feb 2023, 04:50

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2016-2100', 'name': 'https://access.redhat.com/security/cve/CVE-2016-2100', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1310675', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1310675', 'tags': [], 'refsource': 'MISC'}
Summary It was found that access to private bookmarks of users is not properly restricted in Foreman. This could allow an attacker to view the search terms used in these bookmarks which should be private. Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission.

02 Feb 2023, 16:17

Type Values Removed Values Added
Summary Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission. It was found that access to private bookmarks of users is not properly restricted in Foreman. This could allow an attacker to view the search terms used in these bookmarks which should be private.
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2016-2100 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1310675 -

Information

Published : 2016-05-20 14:59

Updated : 2023-12-10 11:46


NVD link : CVE-2016-2100

Mitre link : CVE-2016-2100

CVE.ORG link : CVE-2016-2100


JSON object : View

Products Affected

theforeman

  • foreman
CWE
CWE-284

Improper Access Control