First published: Mon Sep 16 2024(Updated: )
A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authenticated user with permissions to view and create templates to read any field from Foreman's database. By using specific strings in the loader macros, users can bypass permissions and access sensitive information.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
The Foreman |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8553 has a high severity as it allows authenticated users to read sensitive data from Foreman's database.
CVE-2024-8553 affects The Foreman software that utilizes loader macros in report templates.
To fix CVE-2024-8553, update The Foreman to the latest version that addresses this vulnerability.
Authenticated users with permissions to view and create templates may be impacted by CVE-2024-8553.
CVE-2024-8553 can enable an attacker to exploit loader macros to access unauthorized fields in the Foreman database.