When Infosec and Weed Collide: Handling Administrative Actions Safely
ID: 50c286fb-7b79-5835-b661-a6931d5eb34d
STIX ID: report--50c286fb-7b79-5835-b661-a6931d5eb34d
Feed Name: Black Hills Infosec Blog
Threat Score
A state auditor found a critical design/operational weakness in Ohio’s medical-marijuana grow application webapp where two Commerce employees had unlimited access to reviewer accounts and credentials, enabling untraceable impersonation and potential score/document manipulation; the post explains how such administrative access breaks audit trails and recommends mitigations (self-service password flows, “ride-along” support, and explicit impersonation logging).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
