Medium severity4.3NVD Advisory· Published Sep 10, 2018· Updated Jun 17, 2026
CVE-2016-7078
CVE-2016-7078
Description
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:theforeman:foreman:1.15.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:theforeman:foreman:1.15.0:*:*:*:*:*:*:*
- (no CPE)range: <1.15.0
- (no CPE)range: 1.15.0
Patches
Vulnerability mechanics
References
6- www.securityfocus.com/bid/96385nvdThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- github.com/theforeman/foreman/commit/5f606e11cf39719bf62f8b1f3396861b32387905nvdThird Party Advisory
- projects.theforeman.org/issues/16982nvdVendor Advisory
- seclists.org/oss-sec/2017/q1/470nvdMailing ListThird Party Advisory
- theforeman.org/security.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.