The (1) Organization and (2) Locations APIs in Foreman before 1.11.3 and 1.12.x before 1.12.0-RC1 allow remote authenticated users with unlimited filters to bypass organization and location restrictions and read or modify data for an arbitrary organization by leveraging knowledge of the id of that organization.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2016-08-19T21:00:00

Updated: 2018-02-22T10:57:01

Reserved: 2016-05-02T00:00:00


Link: CVE-2016-4451

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2016-08-19T21:59:08.337

Modified: 2023-02-12T23:21:20.167


Link: CVE-2016-4451

JSON object: View

cve-icon Redhat Information

No data.

CWE