First published: Fri Jul 27 2018(Updated: )
A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an attacker with tenant administration access to elevate privileges.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Cloudforms Management Engine | <5.7.1.3 | |
Redhat Cloudforms | =4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-2632 vulnerability is medium.
The vulnerability ID of the CloudForms vulnerability is CVE-2017-2632.
The logic error in valid_role() in CloudForms allows a tenant administrator to create groups with a higher privilege level than they should have, enabling an attacker with tenant administration access to elevate privileges.
CVE-2017-2632 affects Redhat Cloudforms Management Engine versions up to but excluding 5.7.1.3 and Redhat Cloudforms version 4.2.
You can find more information about CVE-2017-2632 in the following references: [Red Hat Security Advisory](http://rhn.redhat.com/errata/RHSA-2017-0320.html), [SecurityFocus](http://www.securityfocus.com/bid/96478), [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2632).