Unrated severityNVD Advisory· Published May 8, 2014· Updated May 6, 2026
CVE-2014-0192
CVE-2014-0192
Description
Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof."
Affected products
5cpe:2.3:a:theforeman:foreman:1.4.0:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:theforeman:foreman:1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:theforeman:foreman:1.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:theforeman:foreman:1.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:theforeman:foreman:1.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:theforeman:foreman:1.4.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- bugzilla.redhat.com/show_bug.cginvdPatch
- projects.theforeman.org/issues/5436nvdExploitVendor Advisory
- theforeman.org/security.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.