Actions
Bug #15490
closedCVE-2016-4995 - view_hosts permissions/filters not checked for provisioning template previews
Description
Users who are logged in with permissions to view some hosts are able to preview provisioning templates for any host by specifying its hostname in the URL, as the specific view_hosts permissions and filters aren't checked. If the organization or location features are enabled, the user will still be restricted to their associated orgs/locs.
This can disclose configuration information about the host, including root password hashes if used in preseed/kickstart templates.
Foreman versions 1.11.0 and higher are vulnerable.
Updated by Dominic Cleal almost 9 years ago
Updated by Lukas Zapletal over 8 years ago
- Status changed from Ready For Testing to Closed
- % Done changed from 0 to 100
Applied in changeset c3c186de12be15e55d9582e54659f765304a1073.
Actions