[Bug 989533] VUL-1: CVE-2016-5390: rubygem-foreman: Access to API routes beneath hosts is not filtered for users with view_host permission