CVE-2013-4182 Information
Feb 14, 2021
cve
Description
app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts which allows remote attackers to access arbitrary hosts via an API request.
Reference
http://projects.theforeman.org/issues/2863 http://rhn.redhat.com/errata/RHSA-2013-1196.html http://theforeman.org/manuals/1.2/index.htmlReleasenotesfor1.2.2 https://bugzilla.redhat.com/show_bug.cgi?id=990374
Share on: