CVE-2013-0187: Medium severity theforeman foreman vulnerability
Published May 8, 2014
·Updated
Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request.
Affected Software
1 affected component
theforeman foreman<=1.0
Event History
May 8, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-0187?
CVE-2013-0187 is categorized as a medium severity vulnerability due to the potential for privilege escalation by authenticated users.
2
How do I fix CVE-2013-0187?
To fix CVE-2013-0187, upgrade to Foreman version 1.1 or later.
3
Who is affected by CVE-2013-0187?
CVE-2013-0187 affects all versions of Foreman prior to 1.1, allowing remote authenticated users to escalate privileges.
4
What type of attack does CVE-2013-0187 exploit?
CVE-2013-0187 exploits vulnerabilities in XMLHttpRequest or AJAX requests made by remote authenticated users.
5
Is CVE-2013-0187 easy to exploit?
Yes, CVE-2013-0187 can be easily exploited by authenticated users if they manipulate AJAX requests.