5
CVSSv2

CVE-2014-0192

Published: 08/05/2014 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Foreman 1.4.0 prior to 1.5.0 does not properly restrict access to provisioning template previews, which allows remote malicious users to obtain sensitive information via the hostname parameter, related to "spoof."

Vulnerable Product Search on Vulmon Subscribe to Product

theforeman foreman 1.4.1

theforeman foreman 1.4.3

theforeman foreman 1.4.2

theforeman foreman 1.4.0

theforeman foreman 1.4.4

Vendor Advisories

Foreman 140 before 150 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive information via the hostname parameter, related to "spoof" ...