Project

General

Profile

Actions

Bug #3060

open

Remove YAML host permissions from basic users,

Added by Jim Perrin over 10 years ago. Updated about 7 years ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Users, Roles and Permissions
Target version:
-
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

A default user with no permissions granted, can view a host and click the 'yaml' option, which will output a rootpw hash. This is not ideal and with the appropriate rainbow tables or similar toolkit could lead to a compromise.


Related issues 2 (1 open1 closed)

Related to Foreman - Bug #2069: (encrypted) root passwords are world readableClosedDominic Cleal10/07/2009Actions
Related to Foreman - Bug #5878: Reports - view_reports role gives view_hosts roleNew05/22/2014Actions
Actions

Also available in: Atom PDF