ZeroHour

CVE-2016-4995

CVSS 3.0
5.3 medium
EPSS
1%p63
Published
()
Modified
Description

Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.

Vendors
theforeman
Products
foreman
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.