CVE-2015-1844
foreman: API not scoping resources to taxonomies
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Foreman before 1.7.5 allows remote authenticated users to bypass organization and location restrictions by connecting through the REST API.
Vulnerabilidad en Foreman en versiones anteriores a 1.7.5, permite a usuarios remotos autenticados eludir las restricciones de organización y localización conectándose a través de la API REST.
A flaw was found in the way foreman authorized user actions on resources via the API when an organization was not explicitly set. A remote attacker could use this flaw to obtain additional information about resources they were not authorized to access.
Red Hat Satellite is a systems management tool for Linux-based infrastructures. It allows for provisioning, remote management and monitoring of multiple Linux deployments with a single, centralized tool. It performs provisioning and configuration management of predefined standard operating environments. This update provides Satellite 6.1 packages for Red Hat Enterprise Linux 7. It was discovered that in Foreman the edit_users permissions allowed the user to edit admin user passwords. An attacker with the edit_users permissions could use this flaw to access an admin user account, leading to an escalation of privileges.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-02-17 CVE Reserved
- 2015-08-12 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-201: Insertion of Sensitive Information Into Sent Data
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
https://groups.google.com/forum/#%21topic/foreman-announce/37KYWhIk4FY | X_refsource_confirm | |
https://groups.google.com/forum/#%21topic/foreman-users/qAGZh5n6n6M | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/theforeman/foreman/pull/2273 | 2023-11-07 |
URL | Date | SRC |
---|---|---|
http://projects.theforeman.org/issues/9947 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2015:1591 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2015:1592 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2015-1844 | 2015-08-12 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1207589 | 2015-08-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Theforeman Search vendor "Theforeman" | Foreman Search vendor "Theforeman" for product "Foreman" | <= 1.7.4 Search vendor "Theforeman" for product "Foreman" and version " <= 1.7.4" | - |
Affected
|