CVE-2017-7505 - CVE House
Back to Database
Status published High CVE-2017-7505

Foreman since version 1.5 is vulnerable to an incorrect authorization...

Vulnerability Description

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-7505

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

foreman
Vulnerable Versions:
1.5 and higher

Timeline

Official Publish: May 26th, 2017
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)