Back

HIGH

Foreman: previous password still allowed to log into foreman with Active Directory backend

Published Oct 6, 2017

Description

The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving the password lifetime period in Active Directory.

Affected products

Remediation

Red Hat statement

Red Hat Product Security determined that this flaw was not a security vulnerability. See the Bugzilla link for more details.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 6, 2017
Updated Aug 6, 2024
Reserved Jul 1, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date Aug 24, 2015