CVE-2014-8183: High severity the foreman vulnerability
Eric Helms of Red Hat reports:
Users can access resources in other organizations via the API if they can guess the name of the resource as access restrictions are not properly enforced.
Other sources
It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8183?
CVE-2014-8183 is classified as a medium severity vulnerability due to improper access control enforcement.
How do I fix CVE-2014-8183?
To remediate CVE-2014-8183, upgrade foreman to version 1.15.6 or later.
What versions of foreman are affected by CVE-2014-8183?
CVE-2014-8183 affects foreman versions 1.x.x before 1.15.6.
Which Red Hat product is affected by CVE-2014-8183?
CVE-2014-8183 affects Red Hat Satellite version 6.0.
What are the consequences of CVE-2014-8183?
The consequences of CVE-2014-8183 include unauthorized access to resources in other organizations if an attacker exploits the vulnerability.