CVE-2017-7505: High severity theforeman foreman vulnerability
Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7505?
CVE-2017-7505 is rated as a medium severity vulnerability due to the potential for unauthorized access to administrator-level functionalities.
How do I fix CVE-2017-7505?
To fix CVE-2017-7505, update Forsman to version 1.15 or later, which addresses the incorrect authorization check.
What versions are affected by CVE-2017-7505?
CVE-2017-7505 affects Foreman versions ranging from 1.5.0 to 1.14.3.
Can CVE-2017-7505 allow unauthorized actions on administrator user objects?
Yes, CVE-2017-7505 enables users with specific permissions to perform unauthorized actions on administrator user objects outside their scope.
Is CVE-2017-7505 a critical vulnerability?
CVE-2017-7505 is not classified as critical but poses significant risks of unauthorized access to sensitive administrative actions.