logo

When Infosec and Weed Collide: Handling Administrative Actions Safely

ID: 50c286fb-7b79-5835-b661-a6931d5eb34d

STIX ID: report--50c286fb-7b79-5835-b661-a6931d5eb34d

Feed Name: Black Hills Infosec Blog

Threat Score
50/100

Date Published: 2018-02-20

Date Updated: 2026-04-27

Author: BHIS

...
...

A state auditor found a critical design/operational weakness in Ohio’s medical-marijuana grow application webapp where two Commerce employees had unlimited access to reviewer accounts and credentials, enabling untraceable impersonation and potential score/document manipulation; the post explains how such administrative access breaks audit trails and recommends mitigations (self-service password flows, “ride-along” support, and explicit impersonation logging).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.