REDHAT-BUG-1092354: Medium severity foreman vulnerability
Ohad Levy of Red Hat reports:
since 1e0fd283 it is possible to override spoof by providing a hostname parameters.
this would allow to retrieve any template of any host bypassing authentication.
External references: http://projects.theforeman.org/issues/5436 http://projects.theforeman.org/projects/foreman/repository/revisions/1e0fd283180dc6bda30c880898cdea69cb579194
Fixed in: https://github.com/theforeman/foreman/pull/1404 https://github.com/theforeman/foreman/commit/aa0ebe8
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1092354?
The vulnerability REDHAT-BUG-1092354 allows unauthorized access to templates, indicating a high severity due to potential data exposure.
How do I fix REDHAT-BUG-1092354?
To address REDHAT-BUG-1092354, update Red Hat Foreman to a version that includes the fix for the hostname parameter override issue.
Who reported REDHAT-BUG-1092354?
REDHAT-BUG-1092354 was reported by Ohad Levy of Red Hat.
What can be exploited in REDHAT-BUG-1092354?
REDHAT-BUG-1092354 can be exploited to bypass authentication and retrieve templates from any host.
Which versions of Red Hat Foreman are affected by REDHAT-BUG-1092354?
Versions of Red Hat Foreman prior to the commit 1e0fd283 are affected by REDHAT-BUG-1092354.