PT-2014-3494 · Red Hat · Red Hat Cloudforms
CVE-2014-0136
·
Publicado
2014-10-27
·
Atualizado
2023-02-13
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat CloudForms 3.0 Management Engine (CFME) version 5.x
Description
The issue concerns the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME), where the
get and log methods allow remote attackers to insert arbitrary text into log files.Recommendations
For version 5.x, consider restricting access to the AgentController to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider disabling the
log method in the AgentController to prevent arbitrary text insertion into log files.Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat Cloudforms