CVE-2016-2100: Medium severity the foreman vulnerability
Published May 20, 2016
·Updated
Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) editbookmarks or (2) destroybookmarks permission.
Affected Software
3 affected components
theforeman foreman<=1.10.2
theforeman foreman=1.11.0
theforeman foreman=1.11.0-rc1
Event History
May 20, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2100?
CVE-2016-2100 is considered a medium severity vulnerability affecting Foreman.
2
How do I fix CVE-2016-2100?
To fix CVE-2016-2100, upgrade Foreman to version 1.10.3 or later, or to version 1.11.0-RC2 or later.
3
What are the potential impacts of CVE-2016-2100?
The potential impacts of CVE-2016-2100 include unauthorized access to private bookmarks, allowing modification or deletion of data.
4
Who is affected by CVE-2016-2100?
CVE-2016-2100 affects users of Foreman versions prior to 1.10.3 and 1.11.0-RC2.
5
What permissions are involved in CVE-2016-2100?
CVE-2016-2100 involves the edit_bookmarks and destroy_bookmarks permissions used by remote authenticated users.