First published: Mon Jun 22 2020(Updated: )
A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution through NFS schedule backup. An attacker logged into the management console could use this flaw to execute arbitrary shell commands on the CloudForms server as root.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Cloudforms Management Engine | =5.10 | |
Redhat Cloudforms Management Engine | =5.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14894 is a vulnerability in the CloudForms management engine version 5.10 and CloudForms management version 5.11 that allows remote code execution through NFS schedule backup.
An attacker logged into the management console can use this vulnerability to execute arbitrary shell commands on the CloudForms server.
The severity of CVE-2019-14894 is critical with a CVSS score of 7.2.
To fix CVE-2019-14894, update the CloudForms management engine to version 5.12 or higher.
For more information about CVE-2019-14894, refer to the Red Hat Bugzilla page: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14894.