Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7505

Опубликовано: 26 мая 2017
Источник: debian
EPSS Низкий

Описание

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
foremanitppackage

EPSS

Процентиль: 53%
0.00306
Низкий

Связанные уязвимости

CVSS3: 7.2
redhat
больше 8 лет назад

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.

CVSS3: 8.8
nvd
больше 8 лет назад

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.

CVSS3: 8.8
github
больше 3 лет назад

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.

EPSS

Процентиль: 53%
0.00306
Низкий
Уязвимость CVE-2017-7505