Security Advisory

CVE-2016-4995

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2016-08-19 21:00:00
Last updated 2024-08-06 00:46:40
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.