ZeroHour

CVE-2016-7077

PoC
CVSS 3.0
4.3 medium
EPSS
1%p70
Published
()
Modified
Description

foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.

Vendors
theforeman
Products
foreman
Weakness
CWE-285, CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.