PT-2021-11172 · Red Hat · Cloudforms

Published

2021-06-07

·

Updated

2022-10-21

·

CVE-2020-25716

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Cloudforms versions prior to 5.11.10.1
Description: A role-based privileges escalation flaw exists, allowing the export or import of administrator files. This enables an attacker with a specific group to perform actions restricted to system administrators, affecting data confidentiality and integrity.
Recommendations: For versions prior to 5.11.10.1, update to version 5.11.10.1 or later to resolve the issue. As a temporary workaround, consider restricting access to administrator files and limiting the privileges of specific groups to minimize the risk of exploitation.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2020-25716
RHSA-2020:5554

Affected Products

Cloudforms