First published: Thu Mar 23 2017(Updated: )
CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within the rails application portion of CloudForms to escalate privileges.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Cloudforms | =4.2 | |
Redhat Cloudforms | =4.6 | |
Redhat Cloudforms Management Engine | <5.7.3 | |
Redhat Cloudforms Management Engine | >=5.8<5.8.1 | |
redhat/cfme | <5.7.3 | 5.7.3 |
redhat/cfme | <5.8.1 | 5.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.