PT-2020-3568 · Red Hat · Red Hat Cloudforms

Published

2020-08-03

·

Updated

2021-07-21

·

CVE-2020-10778

CVSS v2.0

8.0

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions Red Hat CloudForms versions 4.7 through 5
Description The issue is related to a business logic flaw in the Red Hat CloudForms platform, specifically concerning the management of virtual environments. This flaw allows an attacker to edit read-only widgets by inspecting the forms, removing the disabled attribute from the fields, and bypassing server-side validation. This exploit violates the expected behavior of the system.
Recommendations For Red Hat CloudForms versions 4.7 through 5, as a temporary workaround, consider disabling the editing functionality of read-only widgets until a patch is available. Restrict access to the forms that allow widget editing to minimize the risk of exploitation. Avoid using the disabled attribute as the sole means of securing widgets, and instead, implement server-side validation to enforce access controls. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03901
CVE-2020-10778
RHSA-2020:3358
RHSA-2020:3574

Affected Products

Red Hat Cloudforms