CVE-2017-7505

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
VendorProductVersion
theforemanforeman
1.5.0
theforemanforeman
1.5.0:rc1
theforemanforeman
1.5.0:rc2
theforemanforeman
1.5.1
theforemanforeman
1.5.2
theforemanforeman
1.5.3
theforemanforeman
1.6.0
theforemanforeman
1.6.0:rc1
theforemanforeman
1.6.0:rc2
theforemanforeman
1.6.1
theforemanforeman
1.6.3
theforemanforeman
1.7.0
theforemanforeman
1.7.0:rc1
theforemanforeman
1.7.0:rc2
theforemanforeman
1.7.1
theforemanforeman
1.7.2
theforemanforeman
1.7.3
theforemanforeman
1.7.4
theforemanforeman
1.7.5
theforemanforeman
1.8.0
theforemanforeman
1.8.0:rc1
theforemanforeman
1.8.0:rc2
theforemanforeman
1.8.0:rc3
theforemanforeman
1.8.1
theforemanforeman
1.8.2
theforemanforeman
1.8.3
theforemanforeman
1.8.4
theforemanforeman
1.9.0
theforemanforeman
1.9.0:rc1
theforemanforeman
1.9.0:rc2
theforemanforeman
1.9.0:rc3
theforemanforeman
1.9.1
theforemanforeman
1.9.2
theforemanforeman
1.9.3
theforemanforeman
1.10.0
theforemanforeman
1.10.0:rc1
theforemanforeman
1.10.0:rc2
theforemanforeman
1.10.0:rc3
theforemanforeman
1.10.1
theforemanforeman
1.10.2
theforemanforeman
1.10.3
theforemanforeman
1.10.4
theforemanforeman
1.11.0
theforemanforeman
1.11.0:rc1
theforemanforeman
1.11.0:rc2
theforemanforeman
1.11.0:rc3
theforemanforeman
1.11.1
theforemanforeman
1.11.2
theforemanforeman
1.11.3
theforemanforeman
1.11.4
theforemanforeman
1.12.0
theforemanforeman
1.12.0:rc1
theforemanforeman
1.12.0:rc2
theforemanforeman
1.12.0:rc3
theforemanforeman
1.12.1
theforemanforeman
1.12.2
theforemanforeman
1.12.3
theforemanforeman
1.12.4
theforemanforeman
1.13.0
theforemanforeman
1.13.0:rc1
theforemanforeman
1.13.0:rc2
theforemanforeman
1.13.1
theforemanforeman
1.13.2
theforemanforeman
1.13.3
theforemanforeman
1.13.4
theforemanforeman
1.14.0
theforemanforeman
1.14.0:rc1
theforemanforeman
1.14.0:rc2
theforemanforeman
1.14.0:rc3
theforemanforeman
1.14.1
theforemanforeman
1.14.2
theforemanforeman
1.14.3
theforemanforeman
1.15.0
theforemanforeman
1.15.0:rc1
theforemanforeman
1.15.0:rc2
𝑥
= Vulnerable software versions