CVE-2016-7077 PUBLISHED CVSS 4.300000190734863 MEDIUM

foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.

EPSS 0.25% · 48.2th percentile

Risk Scores

CVSS v3.0
4.300000190734863
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.25%
48.2th percentile

Affected Products

VendorProductVersions
theforemanforeman0
Foremanforemanforeman 1.14.0

Timeline

References

Open in Interactive Console →