Beveiligingsadvies

CVE-2013-2113

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2013-07-31 10:00:00
Laatst bijgewerkt 2024-08-06 15:27:40
Toegewezen door redhat
CVSS-score geen score
Status PUBLISHED

Beschrijving

The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role.