CVE-2013-4182
16.09.2013, 19:14
app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | openstack | 3.0 |
theforeman | foreman | 𝑥 ≤ 1.2.1 |
theforeman | foreman | 1.2.0 |
theforeman | foreman | 1.2.0:rc1 |
theforeman | foreman | 1.2.0:rc2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References