Foreman since version 1.5 is vulnerable to an incorrect authorization...
Vulnerability Description
Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-7505
Credits & Attribution
No credits recorded in the NVD database.
References
More from Foreman
View All →Affected Vendor
Foreman
View all reports →