CVE-2016-4475

The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass organization and location restrictions and (a) read, (b) edit, or (c) delete arbitrary organizations or locations via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:foreman:1.12.0:*:*:*:*:*:*:*

History

12 Feb 2023, 23:21

Type Values Removed Values Added
References
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1342439', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1342439', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2016-4475', 'name': 'https://access.redhat.com/security/cve/CVE-2016-4475', 'tags': [], 'refsource': 'MISC'}
Summary It was found that the foreman API and UI actions and URLs are not properly limited to the organizations and locations they were assigned to. This could allow an attacker to view and update other organizations and locations in the system that they should not be allowed to. The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass organization and location restrictions and (a) read, (b) edit, or (c) delete arbitrary organizations or locations via unspecified vectors.

02 Feb 2023, 16:17

Type Values Removed Values Added
References
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1342439 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2016-4475 -
Summary The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass organization and location restrictions and (a) read, (b) edit, or (c) delete arbitrary organizations or locations via unspecified vectors. It was found that the foreman API and UI actions and URLs are not properly limited to the organizations and locations they were assigned to. This could allow an attacker to view and update other organizations and locations in the system that they should not be allowed to.

Information

Published : 2016-08-19 21:59

Updated : 2023-12-10 11:46


NVD link : CVE-2016-4475

Mitre link : CVE-2016-4475

CVE.ORG link : CVE-2016-4475


JSON object : View

Products Affected

theforeman

  • foreman
CWE
CWE-254

7PK - Security Features