Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r979-3cmv-8p2v

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.

EPSS

Процентиль: 53%
0.00306
Низкий

8.8 High

CVSS3

Дефекты

CWE-269
CWE-863

Связанные уязвимости

CVSS3: 7.2
redhat
больше 8 лет назад

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.

CVSS3: 8.8
nvd
больше 8 лет назад

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.

CVSS3: 8.8
debian
больше 8 лет назад

Foreman since version 1.5 is vulnerable to an incorrect authorization ...

EPSS

Процентиль: 53%
0.00306
Низкий

8.8 High

CVSS3

Дефекты

CWE-269
CWE-863