PT-2016-6404 · Foreman · Foreman

Adam Mariš

·

Publicado

2016-08-19

·

Atualizado

2019-03-08

·

CVE-2016-5390

CVSS v3.1

5.3

Média

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Foreman versions prior to 1.11.4 Foreman versions 1.12.x prior to 1.12.1
Description The issue allows remote authenticated users with specific permissions to obtain sensitive network interface information. This can be achieved via a request to API routes beneath "hosts", for example, a GET request to api/v2/hosts/secrethost/interfaces.
Recommendations For Foreman versions prior to 1.11.4, update to version 1.11.4 or later. For Foreman versions 1.12.x prior to 1.12.1, update to version 1.12.1 or later.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-5390

Produtos afetados

Foreman