PT-2018-8390 · Red Hat · Cloudforms

Published

2018-07-27

·

Updated

2023-02-12

·

CVE-2017-7497

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions CloudForms (affected versions not specified)
Description The issue concerns the dialog for creating cloud volumes in CloudForms, specifically with the cinder provider, where it fails to filter cloud tenants by user. This allows an attacker, who has the capability to create storage volumes, to create volumes for any other tenant, potentially leading to unauthorized access or data breaches.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2017-7497
RHSA-2017:1601
RHSA-2017:1758

Affected Products

Cloudforms