Medium severity6.3NVD Advisory· Published Oct 31, 2024· Updated Apr 15, 2026
CVE-2024-8553
CVE-2024-8553
Description
A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authenticated user with permissions to view and create templates to read any field from Foreman's database. By using specific strings in the loader macros, users can bypass permissions and access sensitive information.
Affected products
1- Package: https://rubygems.org/gems/foreman
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6News mentions
0No linked articles in our index yet.