The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2013-07-31T10:00:00Z
Updated: 2013-07-31T10:00:00Z
Reserved: 2013-02-19T00:00:00Z
Link: CVE-2013-2113
JSON object: View
NVD Information
Status : Modified
Published: 2013-07-31T13:20:25.083
Modified: 2023-02-13T04:42:52.227
Link: CVE-2013-2113
JSON object: View
Redhat Information
No data.
CWE