First published: Thu Sep 08 2016(Updated: )
A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Cloudforms | =4.2 | |
Redhat Cloudforms | =4.5 | |
Redhat Cloudforms Management Engine | >=5.6<5.6.3.0 | |
Redhat Cloudforms Management Engine | >=5.7<5.7.3.1 | |
Redhat Cloudforms Management Engine | >=5.8<5.8.1.2 | |
redhat/cfme | <5.8.1.2 | 5.8.1.2 |
redhat/cfme | <5.7.3.1 | 5.7.3.1 |
redhat/cfme | <5.6.3.0 | 5.6.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.