REDHAT-BUG-1232366: High severity foreman vulnerability
Dominic Cleal of Red Hat reported the below issue in Foreman:
A user with the editusers permission (e.g. with the Manager role) is allowed to edit admin users. This allows them to change the password of the admin user's account and gain access to it.
Upstream bug: http://projects.theforeman.org/issues/10829 Upstream fix: pull request not yet merged, see upstream bug
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1232366?
The severity of REDHAT-BUG-1232366 is considered high due to the potential for unauthorized access to admin accounts.
How do I fix REDHAT-BUG-1232366?
To fix REDHAT-BUG-1232366, ensure that users with the edit_users permission are not granted the ability to edit admin accounts.
Who is affected by REDHAT-BUG-1232366?
All users of Red Hat Foreman with roles that include edit_users permission are affected by REDHAT-BUG-1232366.
Can I exploit REDHAT-BUG-1232366 if I have the Manager role?
Yes, if you have the Manager role with edit_users permission, you can exploit REDHAT-BUG-1232366 to change admin user passwords.
What should I do if I believe my admin account has been compromised due to REDHAT-BUG-1232366?
If you suspect your admin account has been compromised due to REDHAT-BUG-1232366, immediately reset your password and review user permissions.