CVE-2015-3235

Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.
Configurations

Configuration 1 (hide)

cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*

History

13 Feb 2023, 00:48

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2015-3235', 'name': 'https://access.redhat.com/security/cve/CVE-2015-3235', 'tags': [], 'refsource': 'MISC'}
Summary It was discovered that in Foreman the edit_users permissions (for example, granted to the Manager role) allowed the user to edit admin user passwords. An attacker with the edit_users permissions could use this flaw to access an admin user account, leading to an escalation of privileges. Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.

02 Feb 2023, 20:20

Type Values Removed Values Added
Summary Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors. It was discovered that in Foreman the edit_users permissions (for example, granted to the Manager role) allowed the user to edit admin user passwords. An attacker with the edit_users permissions could use this flaw to access an admin user account, leading to an escalation of privileges.
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2015-3235 -

Information

Published : 2015-08-14 18:59

Updated : 2023-12-10 11:46


NVD link : CVE-2015-3235

Mitre link : CVE-2015-3235

CVE.ORG link : CVE-2015-3235


JSON object : View

Products Affected

theforeman

  • foreman
CWE
CWE-264

Permissions, Privileges, and Access Controls