First published: Tue Jun 16 2020(Updated: )
In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavior.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Cloudforms | =4.7 | |
Redhat Cloudforms | =5.0.0 | |
redhat/cfme-gemset | <5.11.7.1 | 5.11.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10778 is a vulnerability in Red Hat CloudForms 4.7 and 5 that allows read-only widgets to be edited by inspecting the forms and removing the disabled attribute.
CVE-2020-10778 has a severity value of 6, indicating a high severity.
CVE-2020-10778 violates expected behavior by allowing the editing of read-only widgets without server-side validation.
Red Hat CloudForms 4.7 and 5.0.0 are affected by CVE-2020-10778.
To fix CVE-2020-10778, update to Red Hat CloudForms 5.11.7.1.