CVE-2016-7077
foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.
- Affected products
- Foreman
- Theforeman Foreman
- < 1.14.0
- Fix
- Available
- CVSS 3.0
- 4.3 MEDIUM
- EPSS
- 1.4% (69th percentile)
- Weakness
- CWE-200, CWE-285
- NVD status
- Modified
- Published
- 2018-09-10
CVE-2016-7077 at NVD
No indexed exploits for CVE-2016-7077 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2016-7077 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.