LWN.net Logo

Foreman: multiple vulnerabilities

Package(s):Foreman CVE #(s):CVE-2013-4180 CVE-2013-4182
Created:September 4, 2013 Updated:September 5, 2013
Description: From the Red Hat advisory:

A flaw was found in the API where insufficient privilege checks were conducted by the hosts controller, allowing any user with API access to control any host. (CVE-2013-4182)

A denial of service flaw was found in Foreman in the way user input was converted to a symbol. An authenticated user could create inputs that would lead to excessive memory consumption. (CVE-2013-4180)

Alerts:
Red Hat RHSA-2013:1196-01 2013-09-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds