CVE-2024-8553 - Foreman Data Disclosure Permissions Bypass

3 weeks ago 9
ARTICLE AD BOX
CVE ID : CVE-2024-8553
Published : Oct. 31, 2024, 3:15 p.m. | 24 minutes ago
Description : A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authenticated user with permissions to view and create templates to read any field from Foreman's database. By using specific strings in the loader macros, users can bypass permissions and access sensitive information.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article