Vulnerabilities > Theforeman > Foreman > 1.12.0

DATE CVE VULNERABILITY TITLE RISK
2016-08-19 CVE-2016-5390 Information Exposure vulnerability in Theforeman Foreman
Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitive network interface information via a request to API routes beneath "hosts," as demonstrated by a GET request to api/v2/hosts/secrethost/interfaces.
network
high complexity
theforeman CWE-200
5.3
2016-08-19 CVE-2016-4995 Information Exposure vulnerability in Theforeman Foreman
Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.
network
high complexity
theforeman CWE-200
5.3
2016-08-19 CVE-2016-4475 7PK - Security Features vulnerability in Theforeman Foreman
The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass organization and location restrictions and (a) read, (b) edit, or (c) delete arbitrary organizations or locations via unspecified vectors.
network
low complexity
theforeman CWE-254
8.8
2016-08-19 CVE-2016-4451 7PK - Security Features vulnerability in Theforeman Foreman
The (1) Organization and (2) Locations APIs in Foreman before 1.11.3 and 1.12.x before 1.12.0-RC1 allow remote authenticated users with unlimited filters to bypass organization and location restrictions and read or modify data for an arbitrary organization by leveraging knowledge of the id of that organization.
network
high complexity
theforeman CWE-254
5.0