CVE-2016-7078 Vulnerability Details

  /     /     /  

CVE-2016-7078 Metadata Quick Info

CVE Published: 10/09/2018 | CVE Updated: 06/08/2024 | CVE Year: 2016
Source: redhat | Vendor: Foreman | Product: foreman
Status : PUBLISHED

CVE-2016-7078 Description

foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator\'s view). The user\'s actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-285
CWE Name: CWE-285
Source: Foreman

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).