CVE-2016-7047

Source
https://cve.org/CVERecord?id=CVE-2016-7047
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7047.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-7047
Downstream
Published
2018-09-11T13:29:00.590Z
Modified
2026-03-15T22:10:37.030399Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "4.2"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "4.5"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "5.6"
            },
            {
                "fixed": "5.6.3.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "5.7"
            },
            {
                "fixed": "5.7.3.1"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "5.8"
            },
            {
                "fixed": "5.8.1.2"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7047.json"