CVE-2013-4182: High severity red hat openstack for ibm power vulnerability
app/controllers/api/v1/hostscontroller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.
Other sources
Marek Hulan <mhulan> reports:
Hello,
today it was discovered a community member (Daniel Lobato) that users can manage hosts via API even when they shouldn't have access to them (works right in UI). The app/controllers/api/v1/hostscontroller.rb does not honor user privileges at all.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4182?
CVE-2013-4182 is classified as a high severity vulnerability due to the potential for unauthorized access to hosts.
How do I fix CVE-2013-4182?
To fix CVE-2013-4182, upgrade Foreman to version 1.2.2 or later.
Which versions of Foreman are affected by CVE-2013-4182?
CVE-2013-4182 affects Foreman versions up to and including 1.2.1.
Is Red Hat OpenStack affected by CVE-2013-4182?
Yes, Red Hat OpenStack version 3.0 is affected by CVE-2013-4182.
What type of attack can be executed using CVE-2013-4182?
CVE-2013-4182 allows remote attackers to access arbitrary hosts via an API request.