First published: Fri May 26 2017(Updated: )
Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
TheForeman Foreman | =1.5.0 | |
TheForeman Foreman | =1.5.0-rc1 | |
TheForeman Foreman | =1.5.0-rc2 | |
TheForeman Foreman | =1.5.1 | |
TheForeman Foreman | =1.5.2 | |
TheForeman Foreman | =1.5.3 | |
TheForeman Foreman | =1.6.0 | |
TheForeman Foreman | =1.6.0-rc1 | |
TheForeman Foreman | =1.6.0-rc2 | |
TheForeman Foreman | =1.6.1 | |
TheForeman Foreman | =1.6.3 | |
TheForeman Foreman | =1.7.0 | |
TheForeman Foreman | =1.7.0-rc1 | |
TheForeman Foreman | =1.7.0-rc2 | |
TheForeman Foreman | =1.7.1 | |
TheForeman Foreman | =1.7.2 | |
TheForeman Foreman | =1.7.3 | |
TheForeman Foreman | =1.7.4 | |
TheForeman Foreman | =1.7.5 | |
TheForeman Foreman | =1.8.0 | |
TheForeman Foreman | =1.8.0-rc1 | |
TheForeman Foreman | =1.8.0-rc2 | |
TheForeman Foreman | =1.8.0-rc3 | |
TheForeman Foreman | =1.8.1 | |
TheForeman Foreman | =1.8.2 | |
TheForeman Foreman | =1.8.3 | |
TheForeman Foreman | =1.8.4 | |
TheForeman Foreman | =1.9.0 | |
TheForeman Foreman | =1.9.0-rc1 | |
TheForeman Foreman | =1.9.0-rc2 | |
TheForeman Foreman | =1.9.0-rc3 | |
TheForeman Foreman | =1.9.1 | |
TheForeman Foreman | =1.9.2 | |
TheForeman Foreman | =1.9.3 | |
TheForeman Foreman | =1.10.0 | |
TheForeman Foreman | =1.10.0-rc1 | |
TheForeman Foreman | =1.10.0-rc2 | |
TheForeman Foreman | =1.10.0-rc3 | |
TheForeman Foreman | =1.10.1 | |
TheForeman Foreman | =1.10.2 | |
TheForeman Foreman | =1.10.3 | |
TheForeman Foreman | =1.10.4 | |
TheForeman Foreman | =1.11.0 | |
TheForeman Foreman | =1.11.0-rc1 | |
TheForeman Foreman | =1.11.0-rc2 | |
TheForeman Foreman | =1.11.0-rc3 | |
TheForeman Foreman | =1.11.1 | |
TheForeman Foreman | =1.11.2 | |
TheForeman Foreman | =1.11.3 | |
TheForeman Foreman | =1.11.4 | |
TheForeman Foreman | =1.12.0 | |
TheForeman Foreman | =1.12.0-rc1 | |
TheForeman Foreman | =1.12.0-rc2 | |
TheForeman Foreman | =1.12.0-rc3 | |
TheForeman Foreman | =1.12.1 | |
TheForeman Foreman | =1.12.2 | |
TheForeman Foreman | =1.12.3 | |
TheForeman Foreman | =1.12.4 | |
TheForeman Foreman | =1.13.0 | |
TheForeman Foreman | =1.13.0-rc1 | |
TheForeman Foreman | =1.13.0-rc2 | |
TheForeman Foreman | =1.13.1 | |
TheForeman Foreman | =1.13.2 | |
TheForeman Foreman | =1.13.3 | |
TheForeman Foreman | =1.13.4 | |
TheForeman Foreman | =1.14.0 | |
TheForeman Foreman | =1.14.0-rc1 | |
TheForeman Foreman | =1.14.0-rc2 | |
TheForeman Foreman | =1.14.0-rc3 | |
TheForeman Foreman | =1.14.1 | |
TheForeman Foreman | =1.14.2 | |
TheForeman Foreman | =1.14.3 | |
TheForeman Foreman | =1.15.0 | |
TheForeman Foreman | =1.15.0-rc1 | |
TheForeman Foreman | =1.15.0-rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7505 is rated as a medium severity vulnerability due to the potential for unauthorized access to administrator-level functionalities.
To fix CVE-2017-7505, update Forsman to version 1.15 or later, which addresses the incorrect authorization check.
CVE-2017-7505 affects Foreman versions ranging from 1.5.0 to 1.14.3.
Yes, CVE-2017-7505 enables users with specific permissions to perform unauthorized actions on administrator user objects outside their scope.
CVE-2017-7505 is not classified as critical but poses significant risks of unauthorized access to sensitive administrative actions.