CVE-2015-3235 Information

Description

Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.

Reference

http://projects.theforeman.org/issues/10829 http://theforeman.org/manuals/1.9/index.htmlReleasenotesfor1.9 https://access.redhat.com/errata/RHSA-2015:1591 https://access.redhat.com/errata/RHSA-2015:1592 https://bugzilla.redhat.com/show_bug.cgi?id=1232366

Share on: