CVE-2017-7505

Impact:
Moderate
Public Date:
2017-05-22
CWE:
CWE-863
Bugzilla:
1454392: CVE-2017-7505 foreman: Users with user management permission assigned to organization can manage user objects outside of the organization

The MITRE CVE dictionary describes this issue as:

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.

Find out more about CVE-2017-7505 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 7.2
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required High
User Interaction None
Scope Unchanged
Confidentiality High
Integrity Impact High
Availability Impact High

Affected Packages State

Platform Package State
Red Hat Satellite 6 foreman Will not fix
Red Hat Ceph Storage 1.3 foreman Will not fix

Acknowledgements

This issue was discovered by David Caplan (Red Hat).

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.