CVE Vulnerabilities

CVE-2014-0192

Published: May 08, 2014 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to spoof.

Affected Software

Name Vendor Start Version End Version
Foreman Theforeman 1.4.0 (including) 1.4.0 (including)
Foreman Theforeman 1.4.1 (including) 1.4.1 (including)
Foreman Theforeman 1.4.2 (including) 1.4.2 (including)
Foreman Theforeman 1.4.3 (including) 1.4.3 (including)
Foreman Theforeman 1.4.4 (including) 1.4.4 (including)

References