Red Hat Bugzilla – Bug 1454392
CVE-2017-7505 foreman: Users with user management permission assigned to organization can manage user objects outside of the organization
Last modified: 2017-07-11 23:43:03 EDT
It was found that users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user objects. It's undesirable that users that are supposed to have access only to their organizations can edit global admin accounts including changing their passwords. This issue affects Foreman 1.5 and newer. Upstream bug: http://projects.theforeman.org/issues/19612
Acknowledgments: Name: David Caplan (Red Hat)