CVE-2016-7077: Theforeman Foreman
Medium severity, CVSS 4.3. EPSS: 1.4% chance of exploitation in the next 30 days.
foreman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated objects. Unauthorized user can see names of such objects if their count is less than 6.
Affected products
- Theforeman Foreman: before 1.14.0 (fixed in 1.14.0)
Published 2018-09-10. Last modified 2026-06-17.