Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) editbookmarks or (2) destroybookmarks permission.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-2100.json"