Foreman before 1.7.5 allows remote authenticated users to bypass organization and location restrictions by connecting through the REST API.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1844
Reference (s):
- http://projects.theforeman.org/issues/9947
- https://github.com/theforeman/foreman/pull/2273
- https://groups.google.com/forum/#!topic/foreman-announce/37KYWhIk4FY
- https://groups.google.com/forum/#!topic/foreman-users/qAGZh5n6n6M
- REDHAT:RHSA-2015:1591

