Vulnerability Description
Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Theforeman | Foreman | 1.5.0 |
Related Weaknesses (CWE)
References
- http://projects.theforeman.org/issues/19612Issue TrackingPatchVendor Advisory
- http://www.securityfocus.com/bid/98607Third Party AdvisoryVDB Entry
- https://github.com/theforeman/foreman/pull/4545PatchVendor Advisory
- http://projects.theforeman.org/issues/19612Issue TrackingPatchVendor Advisory
- http://www.securityfocus.com/bid/98607Third Party AdvisoryVDB Entry
- https://github.com/theforeman/foreman/pull/4545PatchVendor Advisory
FAQ
What is CVE-2017-7505?
CVE-2017-7505 is a vulnerability with a CVSS score of 8.8 (HIGH). Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by...
How severe is CVE-2017-7505?
CVE-2017-7505 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7505?
Check the references section above for vendor advisories and patch information. Affected products include: Theforeman Foreman.