A user with the edit_users permission (e.g. with the Manager role) is allowed to edit admin users. This allows them to change the password of the admin user's account and gain access to it. Tracked as CVE-2015-3235. h3. Mitigation Change roles of users with the edit_users permission, remove the "Unlimited" flag and set a search query of "admin = false".
Created from redmine issue http://projects.theforeman.org/issues/10829
Delivered in Snap10
mis clicked.
hi please provide verification steps thanks thanks and regards Tazim
a. As non-admin user, with permission to edit users: 1. Go to users 2. Pick an Admin user (e.g., "admin") and edit 3. Change password Expected result: password can not be changed
VERIFIED: # rpm -qa | grep foreman ruby193-rubygem-foreman-tasks-0.6.12.8-1.el7sat.noarch rubygem-hammer_cli_foreman_docker-0.0.3.9-1.el7sat.noarch foreman-selinux-1.7.2.13-1.el7sat.noarch foreman-ovirt-1.7.2.30-1.el7sat.noarch rubygem-hammer_cli_foreman_bootdisk-0.1.2.7-1.el7sat.noarch foreman-debug-1.7.2.30-1.el7sat.noarch ruby193-rubygem-foreman_bootdisk-4.0.2.13-1.el7sat.noarch foreman-1.7.2.30-1.el7sat.noarch ruby193-rubygem-foreman_docker-1.2.0.18-1.el7sat.noarch ruby193-rubygem-foreman-redhat_access-0.2.0-8.el7sat.noarch rubygem-hammer_cli_foreman_discovery-0.0.1.10-1.el7sat.noarch foreman-proxy-1.7.2.5-1.el7sat.noarch ibm-x3755-02.ovirt.rhts.eng.bos.redhat.com-foreman-client-1.0-1.noarch ibm-x3755-02.ovirt.rhts.eng.bos.redhat.com-foreman-proxy-client-1.0-1.noarch foreman-compute-1.7.2.30-1.el7sat.noarch foreman-vmware-1.7.2.30-1.el7sat.noarch ruby193-rubygem-foreman_hooks-0.3.7-2.el7sat.noarch rubygem-hammer_cli_foreman-0.1.4.14-1.el7sat.noarch foreman-libvirt-1.7.2.30-1.el7sat.noarch ruby193-rubygem-foreman_gutterball-0.0.1.9-1.el7sat.noarch ibm-x3755-02.ovirt.rhts.eng.bos.redhat.com-foreman-proxy-1.0-1.noarch foreman-gce-1.7.2.30-1.el7sat.noarch rubygem-hammer_cli_foreman_tasks-0.0.3.4-1.el7sat.noarch ruby193-rubygem-foreman_discovery-2.0.0.17-1.el7sat.noarch foreman-postgresql-1.7.2.30-1.el7sat.noarch steps: 1. As non-admin user, with permission to edit users: 2. Go to users 3. Pick an Admin user (e.g., "admin") and edit 4. Change password password can not be changed
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2015:1592