CVE-2013-2113: Red Hat Openstack

Medium severity, CVSS 6.0. EPSS: 20.9% chance of exploitation in the next 30 days.

The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role.

Affected products

  • Red Hat Openstack: version 3.0 only
  • Theforeman Foreman: up to and including 1.2.0; version 1.1 only

Published 2013-07-31. Last modified 2026-06-16.