app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openstack | Redhat | 3.0 (including) | 3.0 (including) |
OpenStack 3 for RHEL 6 | RedHat | ruby193-foreman-0:1.1.10014-1.2.el6ost | * |
Red Hat Satellite 6.0 | RedHat | foreman-0:1.6.0.44-1.el7sat | * |