PT-2026-82490 · Foreman · Foreman
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Foreman (affected versions not specified)
Description
An issue exists where the template revision endpoint fails to enforce object-level authorization when retrieving an audited template revision. An authenticated user with low privileges and template-related permissions, such as
view ptables, can access historical template contents from other organizations or locations by providing the relevant audit ID. This may lead to the unauthorized disclosure of sensitive data, including configuration details, credentials, or secrets. The REST API revision endpoints are not affected by this issue.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Foreman