7.5
CVSSv2

CVE-2013-4182

Published: 16/09/2013 Updated: 13/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

app/controllers/api/v1/hosts_controller.rb in Foreman prior to 1.2.2 does not properly restrict access to hosts, which allows remote malicious users to access arbitrary hosts via an API request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openstack 3.0

theforeman foreman

theforeman foreman 1.2.0

Vendor Advisories

Synopsis Important: Foreman security update Type/Severity Security Advisory: Important Topic Updated Foreman packages that fix two security issues are now available forRed Hat OpenStack 30The Red Hat Security Response Team has rated this update as havingimportant security impact Common Vulnerability Scor ...
app/controllers/api/v1/hosts_controllerrb in Foreman before 122 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request ...