First published: Tue Jun 16 2020(Updated: )
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible to access some sensitive data within the CloudForms.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Cloudforms | =4.7 | |
Redhat Cloudforms | =5.0.0 | |
redhat/cfme-gemset | <5.11.7.1 | 5.11.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue is CVE-2020-10779.
CVE-2020-10779 has a severity level of high.
Red Hat CloudForms 4.7 and 5.0.0 are affected by CVE-2020-10779.
CVE-2020-10779 leads to insecure direct object references (IDOR) and functional level access control bypass in Red Hat CloudForms.
You can find more information about CVE-2020-10779 at the following references: [Reference 1](https://access.redhat.com/errata/RHSA-2020:3358), [Reference 2](https://access.redhat.com/security/cve/cve-2020-10779), [Reference 3](https://bugzilla.redhat.com/show_bug.cgi?id=1847647).