Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3235

Опубликовано: 16 июн. 2015
Источник: redhat
CVSS2: 6.3
EPSS Низкий

Описание

Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.

It was discovered that in Foreman the edit_users permissions (for example, granted to the Manager role) allowed the user to edit admin user passwords. An attacker with the edit_users permissions could use this flaw to access an admin user account, leading to an escalation of privileges.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenStack ForemanforemanWill not fix
Red Hat Satellite 6.1aopallianceFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1apache-commons-codec-eap6FixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1apache-mime4jFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1atinjectFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1bouncycastleFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1c3p0FixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1candlepinFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1candlepin-commonFixedRHSA-2015:159212.08.2015
Red Hat Satellite 6.1candlepin-sclFixedRHSA-2015:159212.08.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=1232366foreman: edit_users permission allows changing of admin passwords

EPSS

Процентиль: 68%
0.0057
Низкий

6.3 Medium

CVSS2

Связанные уязвимости

nvd
больше 10 лет назад

Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.

debian
больше 10 лет назад

Foreman before 1.9.0 allows remote authenticated users with the edit_u ...

github
больше 3 лет назад

Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.

EPSS

Процентиль: 68%
0.0057
Низкий

6.3 Medium

CVSS2

Уязвимость CVE-2015-3235