First published: Tue Jun 16 2020(Updated: )
A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Cloudforms | =4.7 | |
Redhat Cloudforms | =5.0.0 | |
redhat/cfme-gemset | <5.11.7.1 | 5.11.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10777 is a cross-site scripting (XSS) vulnerability found in the Report Menu feature of Red Hat CloudForms 4.7 and 5.
CVE-2020-10777 allows an attacker to execute a stored XSS attack on an application administrator using CloudForms.
CVE-2020-10777 has a severity rating of 5.4 (Medium).
Red Hat CloudForms versions 4.7 and 5.0.0 are affected by CVE-2020-10777.
To fix CVE-2020-10777, you should update Red Hat CloudForms to version 5.11.7.1 or higher.