REDHAT-BUG-2536844: High severity Foreman Foreman vulnerability
When accessing certain API endpoints (e.g. POSTing to /template/preview) a user with the Viewer role is able to access information they should not be able to (i.e. @host.rootpass). When the system is configured insecurely (i.e. Safemode is disabled), or a Safemode bypass vulnerability exists, then the Viewer is able to perform Remote Code Execution on the system as the foreman system account.