Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106424
Category:Web application abuses
Title:Foreman < 1.11.1 Information Disclosure Vulnerability
Summary:Foreman is prone to an information disclosure; vulnerability.
Description:Summary:
Foreman is prone to an information disclosure
vulnerability.

Vulnerability Insight:
A provisioning template containing inspect will expose
sensitive information about the Rails controller and application when rendered when using Safemode
rendering (the default setting). This includes the application secret token, possibly permitting a
privilege escalation.

Affected Software/OS:
Foreman versions prior to 1.11.1.

Solution:
Update to version 1.11.1 or later.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-3693
RHSA-2018:0336
https://access.redhat.com/errata/RHSA-2018:0336
[oss-security] 20160420 CVE-2016-3693: Foreman application information leakage through templates
http://www.openwall.com/lists/oss-security/2016/04/20/8
http://projects.theforeman.org/issues/14635
http://rubysec.com/advisories/CVE-2016-3693/
http://theforeman.org/security.html#2016-3693
https://github.com/svenfuchs/safemode/commit/0f764a1720a3a68fd2842e21377c8bfad6d7126f
https://github.com/theforeman/foreman/commit/82f9b93c54f72c5814df6bab7fad057eab65b2f2
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.