foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.securityfocus.com/bid/94230 | Third Party Advisory VDB Entry | 
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7077 | Issue Tracking Third Party Advisory | 
| https://projects.theforeman.org/issues/16971 | Exploit Vendor Advisory | 
| https://theforeman.org/security.html#2016-7077 | Vendor Advisory | 
| http://www.securityfocus.com/bid/94230 | Third Party Advisory VDB Entry | 
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7077 | Issue Tracking Third Party Advisory | 
| https://projects.theforeman.org/issues/16971 | Exploit Vendor Advisory | 
| https://theforeman.org/security.html#2016-7077 | Vendor Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2018-09-10 15:29
Updated : 2024-11-21 02:57
NVD link : CVE-2016-7077
Mitre link : CVE-2016-7077
CVE.ORG link : CVE-2016-7077
JSON object : View
Products Affected
                theforeman
- foreman
