REDHAT-BUG-1348939: Low severity foreman vulnerability
Dominic Cleal of Red Hat reports:
Users who are logged in with permissions to view some hosts are able to preview provisioning templates for any host by specifying its hostname in the URL, as the specific viewhosts permissions and filters aren't checked. If the organization or location features are enabled, the user will still be restricted to their associated orgs/locs.
This can disclose configuration information about the host, including root password hashes if used in preseed/kickstart templates.
Upstream bug:
http://projects.theforeman.org/issues/15490
Proposed patch:
https://github.com/theforeman/foreman/pull/2428
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1348939?
REDHAT-BUG-1348939 has been classified as a medium severity vulnerability.
How do I fix REDHAT-BUG-1348939?
To fix REDHAT-BUG-1348939, ensure that appropriate permissions are enforced for viewing provisioning templates based on host access.
Who is affected by REDHAT-BUG-1348939?
Users with permissions to view some hosts in Red Hat Foreman may be affected by REDHAT-BUG-1348939.
What type of vulnerability is REDHAT-BUG-1348939?
REDHAT-BUG-1348939 is a local privilege escalation vulnerability originating from inadequate permission checks.
What product does REDHAT-BUG-1348939 impact?
REDHAT-BUG-1348939 impacts the Red Hat Foreman product.