Total vulnerabilities in the database
Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission.
Software | From | Fixed in |
---|---|---|
theforeman / foreman | - | 1.10.2.x |
theforeman / foreman | 1.11.0-rc1 | 1.11.0-rc1.x |
theforeman / foreman | 1.11.0 | 1.11.0.x |