CVE-2016-4475

Severity CVSS v4.0:
Pending analysis
Type:
CWE-254 Security Features
Publication date:
19/08/2016
Last modified:
12/04/2025

Description

The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass organization and location restrictions and (a) read, (b) edit, or (c) delete arbitrary organizations or locations via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:* 1.11.3 (including)
cpe:2.3:a:theforeman:foreman:1.12.0:*:*:*:*:*:*:*