First published: Wed Jun 17 2020(Updated: )
Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group can perform actions restricted only to EVM-Super-administrator group, leads to, exporting or importing administrator files.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Cloudforms | =4.7 | |
Redhat Cloudforms | =5.0.0 | |
redhat/cfme-gemset | <5.11.7.1 | 5.11.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10783 is a role-based privilege escalation flaw in Red Hat CloudForms 4.7 and 5.
The severity of CVE-2020-10783 is high with a CVSS score of 8.3.
CVE-2020-10783 allows an attacker with the EVM-Operator group to perform actions restricted to the EVM-Super-administrator group, leading to the exporting or importing of administrator files.
Red Hat CloudForms 4.7 and 5.0.0 are affected by CVE-2020-10783.
To fix CVE-2020-10783, update Red Hat CloudForms to version 5.11.7.1 or later.