PT-2020-3566 · Red Hat · Red Hat Cloudforms

Alberto Bellotti

+1

·

Published

2020-08-03

·

Updated

2021-07-21

·

CVE-2020-14325

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Red Hat CloudForms versions prior to 5.11.7.0
Description The issue is related to an authorization flaw that allows a malicious attacker to create existing and non-existing role-based access control users, with groups and roles. This can enable an attacker to perform any API request as a super administrator by selecting a specific group, such as EvmGroup-super administrator. The flaw is associated with errors in authorization.
Recommendations For versions prior to 5.11.7.0, update to version 5.11.7.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the EvmGroup-super administrator group to minimize the risk of exploitation. Additionally, restrict API requests to only necessary users and groups to reduce the potential impact of the flaw.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03899
CVE-2020-14325
RHSA-2020:3358
RHSA-2020:3574

Affected Products

Red Hat Cloudforms