First published: Tue Mar 31 2015(Updated: )
Foreman before 1.7.5 allows remote authenticated users to bypass organization and location restrictions by connecting through the REST API.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/foreman | <1.7.5 | 1.7.5 |
TheForeman Foreman | <=1.7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1844 is classified as a medium severity vulnerability due to the potential for unauthorized access to organization information.
To fix CVE-2015-1844, upgrade Foreman to version 1.7.5 or later.
Organizations using Foreman versions before 1.7.5 are affected by CVE-2015-1844.
CVE-2015-1844 is a security vulnerability that involves unauthorized access through the Foreman REST API.
The best mitigation for CVE-2015-1844 is to apply the available upgrade to version 1.7.5, as no alternative workarounds have been documented.