CVE-2015-3235: Theforeman Foreman
Medium severity, CVSS 6.0. EPSS: 1.6% chance of exploitation in the next 30 days.
Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.
Affected products
- Theforeman Foreman: up to and including 1.8.2
Published 2015-08-14. Last modified 2026-06-17.