CVE-2016-5390: Infoleak
Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the viewhosts permission containing a filter to obtain sensitive network interface information via a request to API routes beneath "hosts," as demonstrated by a GET request to api/v2/hosts/secrethost/interfaces.
Other sources
It was reported that non-admin users with the viewhosts permission containing a filter are able to access API routes beneath "hosts" such as GET /api/v2/hosts/secrethost/interfaces without the filter being taken into account. This allows users to access network interface details (including BMC login details) for any host.
Affects Foreman 1.10.0 and higher.
Upstream bug:
http://projects.theforeman.org/issues/15653
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5390?
CVE-2016-5390 has a moderate severity rating, as it allows for unauthorized access to sensitive network interface information.
How do I fix CVE-2016-5390?
To fix CVE-2016-5390, upgrade Foreman to version 1.11.4 or 1.12.1 or later.
Who is affected by CVE-2016-5390?
CVE-2016-5390 affects users of Foreman versions prior to 1.11.4 and 1.12.x before 1.12.1 that have the view_hosts permission.
What type of access does CVE-2016-5390 exploit?
CVE-2016-5390 exploits the access of remote authenticated users with filtered view_hosts permissions.
What information can be leaked due to CVE-2016-5390?
CVE-2016-5390 can leak sensitive network interface information from the API when certain conditions are met.