PT-2020-3569 · Red Hat · Cloudforms

Purnachand Pulahari

+1

·

Published

2020-08-03

·

Updated

2021-07-21

·

CVE-2020-10779

CVSS v2.0

8.0

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions Red Hat CloudForms versions 4.7 through 5
Description The issue is related to insufficient access control in the CloudForms Management Engine, allowing for insecure direct object references (IDOR) and functional level access control bypass due to a missing privilege check. This could enable an attacker, who knows the right criteria, to access sensitive data within CloudForms.
Recommendations For Red Hat CloudForms versions 4.7 through 5, consider restricting access to sensitive data until a patch is available. As a temporary workaround, consider implementing additional access control checks to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03902
CVE-2020-10779
RHSA-2020:3358

Affected Products

Cloudforms