Authentication mechanism absence or evasion In foreman_ansible
Description
Missing Authentication for Critical Function in Foreman Ansible An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rubygems | 2.0.0 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.