CyberRota Analysis
AI-GeneratedA critical vulnerability exists in Foreman that enables authenticated users with low-level Viewer permissions to exploit template preview endpoints, leading to unauthorized information disclosure, including sensitive data like host root passwords. Additionally, in systems with Safemode protections disabled, this flaw could allow the execution of arbitrary commands as the Foreman system account. Organizations using Foreman, particularly those with misconfigured security settings, should prioritize addressing this vulnerability to mitigate potential data breaches and system compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account.