CVE-2019-14894: Input Validation
A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution through NFS schedule backup. An attacker logged into the management console could use this flaw to execute arbitrary shell commands on the CloudForms server as root.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14894?
CVE-2019-14894 is a vulnerability in the CloudForms management engine version 5.10 and CloudForms management version 5.11 that allows remote code execution through NFS schedule backup.
How does CVE-2019-14894 work?
An attacker logged into the management console can use this vulnerability to execute arbitrary shell commands on the CloudForms server.
What is the severity of CVE-2019-14894?
The severity of CVE-2019-14894 is critical with a CVSS score of 7.2.
How can I fix CVE-2019-14894?
To fix CVE-2019-14894, update the CloudForms management engine to version 5.12 or higher.
Where can I find more information about CVE-2019-14894?
For more information about CVE-2019-14894, refer to the Red Hat Bugzilla page: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14894.