Bug #10829

CVE-2015-3235 - edit_users permission allows changing of admin passwords

Added by Dominic Cleal over 1 year ago. Updated over 1 year ago.

Assigned To:Shlomi Zadok
Target version:-
Difficulty: Bugzilla link:1233084
Found in release: Pull request:https://github.com/theforeman/foreman/pull/2465
Story points-
Velocity based estimate-
Release1.9.0Release relationshipAuto


A user with the edit_users permission (e.g. with the Manager role) is allowed to edit admin users. This allows them to change the password of the admin user's account and gain access to it.

Tracked as CVE-2015-3235.


Change roles of users with the edit_users permission, remove the "Unlimited" flag and set a search query of "admin = false".

Associated revisions

Revision f97fbd6f
Added by Shlomi Zadok over 1 year ago

fixes #10829 - non-admin user cannot update admin password


#1 Updated by Shlomi Zadok over 1 year ago

  • Assigned To set to Shlomi Zadok

#2 Updated by The Foreman Bot over 1 year ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/theforeman/foreman/pull/2465 added

#3 Updated by Shlomi Zadok over 1 year ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100

#4 Updated by Ohad Levy over 1 year ago

  • Bugzilla link set to 1233084

Also available in: Atom PDF