Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof."
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2014-05-08T14:00:00

Updated: 2014-05-08T12:57:00

Reserved: 2013-12-03T00:00:00


Link: CVE-2014-0192

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2014-05-08T14:29:14.033

Modified: 2023-02-13T00:36:16.267


Link: CVE-2014-0192

JSON object: View

cve-icon Redhat Information

No data.

CWE