First published: Tue Jun 27 2017(Updated: )
In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing when invoking arbitrary methods via filtering on VMs that MiqExpression will execute that is triggerable by API users. An attacker could use this to execute actions they should not be allowed to (e.g. destroying VMs).
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cfme | <5.7.3 | 5.7.3 |
redhat/cfme | <5.8.1 | 5.8.1 |
Red Hat CloudForms | =4.5 | |
Red Hat CloudForms Management Engine | <5.7.3 | |
Red Hat CloudForms Management Engine | >=5.8.0<5.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7530 is classified as a medium severity vulnerability due to the potential unauthorized access to execute privileged actions.
To fix CVE-2017-7530, update CloudForms Management Engine to version 5.7.3 or 5.8.1 or later.
CVE-2017-7530 affects Red Hat CloudForms Management Engine versions prior to 5.7.3 and versions in the 5.8.x series before 5.8.1.
An attacker exploiting CVE-2017-7530 can invoke arbitrary methods on virtual machines, potentially allowing them to execute unauthorized actions.
Yes, CVE-2017-7530 remains a concern for users who have not yet updated their affected versions of the CloudForms Management Engine.