CVE-2015-1844: Medium severity theforeman foreman vulnerability
Foreman before 1.7.5 allows remote authenticated users to bypass organization and location restrictions by connecting through the REST API.
Other sources
It was discovered that in Foreman API it's possible to retrieve any organization information, if the organization is not explicitely set in the API request. The fix should make sure that if user does not specify an org explicitly - he's scoped to his orgs only. Initially reported in Foreman public mailing list:
https://groups.google.com/forum/#!topic/foreman-users/qAGZh5n6n6M
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1844?
CVE-2015-1844 is classified as a medium severity vulnerability due to the potential for unauthorized access to organization information.
How do I fix CVE-2015-1844?
To fix CVE-2015-1844, upgrade Foreman to version 1.7.5 or later.
Who is affected by CVE-2015-1844?
Organizations using Foreman versions before 1.7.5 are affected by CVE-2015-1844.
What type of vulnerability is CVE-2015-1844?
CVE-2015-1844 is a security vulnerability that involves unauthorized access through the Foreman REST API.
Is there a way to mitigate CVE-2015-1844 without upgrading?
The best mitigation for CVE-2015-1844 is to apply the available upgrade to version 1.7.5, as no alternative workarounds have been documented.