Improper Authorization in Foreman by The Foreman Project
CVE-2017-7505
8.8HIGH
What is CVE-2017-7505?
Foreman versions 1.5 and later exhibit a vulnerability due to improper authorization checks. Users with permission to manage user accounts can exploit this flaw to perform unauthorized actions on administrator accounts outside their organizational scope. This includes sensitive operations such as editing global admin settings and altering passwords, posing significant security risks for systems relying on the Foreman platform.
Affected Version(s)
foreman 1.5 and higher
