PT-2020-3569 · Red Hat · Cloudforms
Purnachand Pulahari
+1
·
Published
2020-08-03
·
Updated
2021-07-21
·
CVE-2020-10779
CVSS v2.0
8.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Red Hat CloudForms versions 4.7 through 5
Description
The issue is related to insufficient access control in the CloudForms Management Engine, allowing for insecure direct object references (IDOR) and functional level access control bypass due to a missing privilege check. This could enable an attacker, who knows the right criteria, to access sensitive data within CloudForms.
Recommendations
For Red Hat CloudForms versions 4.7 through 5, consider restricting access to sensitive data until a patch is available.
As a temporary workaround, consider implementing additional access control checks to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloudforms