Vulnerability Description
app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openstack | 3.0 |
| Theforeman | Foreman | <= 1.2.1 |
Related Weaknesses (CWE)
References
- http://projects.theforeman.org/issues/2863Patch
- http://rhn.redhat.com/errata/RHSA-2013-1196.html
- http://theforeman.org/manuals/1.2/index.html#Releasenotesfor1.2.2
- https://bugzilla.redhat.com/show_bug.cgi?id=990374
- http://projects.theforeman.org/issues/2863Patch
- http://rhn.redhat.com/errata/RHSA-2013-1196.html
- http://theforeman.org/manuals/1.2/index.html#Releasenotesfor1.2.2
- https://bugzilla.redhat.com/show_bug.cgi?id=990374
FAQ
What is CVE-2013-4182?
CVE-2013-4182 is a vulnerability with a CVSS score of 7.5 (HIGH). app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.
How severe is CVE-2013-4182?
CVE-2013-4182 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-4182?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Openstack, Theforeman Foreman.