REDHAT-BUG-1339889: Medium severity foreman vulnerability
Marek Hulán of Red Hat reports:
When accessing Foreman as a user limited to specific organization, having access to other organization IDs and having unlimited filters could allow a user to access/modify other organization data by using the organization ID as an API parameter.
Upstream bug:
http://projects.theforeman.org/issues/15182
Upstream patch:
https://github.com/theforeman/foreman/pull/3553/commits/42066cfa19de316449954079c07bdf1e4cc5eb0a
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1339889?
The severity of REDHAT-BUG-1339889 is considered to be high due to potential unauthorized access to sensitive organization data.
How do I fix REDHAT-BUG-1339889?
To fix REDHAT-BUG-1339889, you should update to the latest version of Red Hat Foreman that addresses this vulnerability.
What is the impact of REDHAT-BUG-1339889?
The impact of REDHAT-BUG-1339889 allows users to access or modify data belonging to other organizations due to inadequate access restrictions.
Who reported REDHAT-BUG-1339889?
REDHAT-BUG-1339889 was reported by Marek Hulán of Red Hat.
Which versions of Foreman are affected by REDHAT-BUG-1339889?
REDHAT-BUG-1339889 affects specific versions of Red Hat Foreman, and users should check their particular version for vulnerabilities.