CVE-2017-15123: Medium severity red hat cloudforms management engine vulnerability
A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created virtual machines.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-15123?
CVE-2017-15123 is a vulnerability in the CloudForms web interface that allows unauthenticated users to view potentially sensitive information.
What is the severity of CVE-2017-15123?
The severity of CVE-2017-15123 is medium with a CVSS score of 5.3.
How does CVE-2017-15123 affect Redhat Cloudforms Management Engine?
CVE-2017-15123 affects Redhat Cloudforms Management Engine versions 5.8 to 5.10.
What can an attacker do with CVE-2017-15123?
An attacker can use CVE-2017-15123 to view potentially sensitive information from CloudForms, such as newly created virtual machines.
How to fix CVE-2017-15123?
To fix CVE-2017-15123, users should update their CloudForms web interface to a version that restricts RSS feed URLs to authenticated users only.