First published: Tue Jul 12 2016(Updated: )
Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitive network interface information via a request to API routes beneath "hosts," as demonstrated by a GET request to api/v2/hosts/secrethost/interfaces.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
TheForeman Foreman | >=1.11.0<1.11.4 | |
TheForeman Foreman | >=1.12.0<1.12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5390 has a moderate severity rating, as it allows for unauthorized access to sensitive network interface information.
To fix CVE-2016-5390, upgrade Foreman to version 1.11.4 or 1.12.1 or later.
CVE-2016-5390 affects users of Foreman versions prior to 1.11.4 and 1.12.x before 1.12.1 that have the view_hosts permission.
CVE-2016-5390 exploits the access of remote authenticated users with filtered view_hosts permissions.
CVE-2016-5390 can leak sensitive network interface information from the API when certain conditions are met.