Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission.
2016-05-20T14:59:02.200
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 5.4 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | theforeman | foreman | ≤ 1.10.2 | Yes |
Application | theforeman | foreman | 1.11.0 | Yes |
Application | theforeman | foreman | 1.11.0 | Yes |