CVE-2020-10777: XSS
Published Jun 16, 2020
·Updated
A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms.
Affected Software
3 affected componentsFixes available
redhat/cfme-gemset<5.11.7.1
5.11.7.1
redhat Cloudforms=4.7
redhat Cloudforms=5.0.0
Event History
Aug 11, 2020
CVE Published
via MITRE·12:17 PM
Data Sourced
via MITRE·12:17 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-10777?
CVE-2020-10777 is a cross-site scripting (XSS) vulnerability found in the Report Menu feature of Red Hat CloudForms 4.7 and 5.
2
How does CVE-2020-10777 impact Red Hat CloudForms?
CVE-2020-10777 allows an attacker to execute a stored XSS attack on an application administrator using CloudForms.
3
How severe is CVE-2020-10777?
CVE-2020-10777 has a severity rating of 5.4 (Medium).
4
Which versions of Red Hat CloudForms are affected by CVE-2020-10777?
Red Hat CloudForms versions 4.7 and 5.0.0 are affected by CVE-2020-10777.
5
How can I fix CVE-2020-10777?
To fix CVE-2020-10777, you should update Red Hat CloudForms to version 5.11.7.1 or higher.