Vulnerability Description
Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Theforeman | Foreman | <= 1.10.2 |
Related Weaknesses (CWE)
References
- http://projects.theforeman.org/issues/13828
- http://theforeman.org/security.html#2016-2100Vendor Advisory
- http://www.openwall.com/lists/oss-security/2016/03/31/2
- https://access.redhat.com/errata/RHBA-2016:1500
- http://projects.theforeman.org/issues/13828
- http://theforeman.org/security.html#2016-2100Vendor Advisory
- http://www.openwall.com/lists/oss-security/2016/03/31/2
- https://access.redhat.com/errata/RHBA-2016:1500
FAQ
What is CVE-2016-2100?
CVE-2016-2100 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permissio...
How severe is CVE-2016-2100?
CVE-2016-2100 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-2100?
Check the references section above for vendor advisories and patch information. Affected products include: Theforeman Foreman.