Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7505

Опубликовано: 22 мая 2017
Источник: redhat
CVSS3: 7.2
EPSS Низкий

Описание

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.3foremanWill not fix
Red Hat Satellite 6foremanUnder investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1454392foreman: Users with user management permission assigned to organization can manage user objects outside of the organization

EPSS

Процентиль: 53%
0.00306
Низкий

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 8 лет назад

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.

CVSS3: 8.8
debian
больше 8 лет назад

Foreman since version 1.5 is vulnerable to an incorrect authorization ...

CVSS3: 8.8
github
больше 3 лет назад

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.

EPSS

Процентиль: 53%
0.00306
Низкий

7.2 High

CVSS3

Уязвимость CVE-2017-7505