CVE-2017-7497: Medium severity redhat CloudForms Management Engine vulnerability
Gellert Kis of Red Hat reports:
Dialog for creating cloud volumes (cinder provider) does not filter cloud tenants for user. In this way users can create storage volumes in any tenant. Not only in their own tenant. This currently affects CFME 5.7.2 and 5.8.0.
Other sources
The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7497?
CVE-2017-7497 is classified as a medium severity vulnerability due to its potential for unauthorized access to create storage volumes across tenants.
How do I fix CVE-2017-7497?
To fix CVE-2017-7497, upgrade the Red Hat CloudForms Management Engine to version 5.8.1 or later.
What versions of software are affected by CVE-2017-7497?
CVE-2017-7497 affects Red Hat CloudForms Management Engine versions 5.7.2 and 5.8.0.
What is the impact of CVE-2017-7497?
The impact of CVE-2017-7497 allows users to create storage volumes in any cloud tenant, leading to potential data exposure.
Who reported CVE-2017-7497?
CVE-2017-7497 was reported by Gellert Kis of Red Hat.