VYPR
Medium severity5.0OSV Advisory· Published Aug 19, 2016· Updated Jun 17, 2026

CVE-2016-4451

CVE-2016-4451

Description

The (1) Organization and (2) Locations APIs in Foreman before 1.11.3 and 1.12.x before 1.12.0-RC1 allow remote authenticated users with unlimited filters to bypass organization and location restrictions and read or modify data for an arbitrary organization by leveraging knowledge of the id of that organization.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Range: 0.1, 0.2, 0.2rc2, …
  • cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*range: <=1.11.2
    • cpe:2.3:a:theforeman:foreman:1.12.0:*:*:*:*:*:*:*
    • (no CPE)range: <1.11.3 or >=1.12.0-RC1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.