RSS   Vulnerabilities for 'Foreman-tasks'   RSS

2019-07-31
 
CVE-2019-10198

CWE-287
 

 
An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through the web UI or API, if they can discover or guess the UUID of the task.

 

 >>> Vendor: Theforeman 9 Products
Katello
Foreman
KAFO
Foreman-tasks
Hammer cli
Foreman azurerm
Smart proxy shell hooks
Foremanfogproxmox
Smart proxy salt


Copyright 2024, cxsecurity.com

 

Back to Top