CVE-2015-3235: Theforeman Foreman

Medium severity, CVSS 6.0. EPSS: 1.6% chance of exploitation in the next 30 days.

Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.

Affected products

Published 2015-08-14. Last modified 2026-06-17.