CVE-2020-14296: SSRF
Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not normally accessible.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-14296?
CVE-2020-14296 is a vulnerability in Red Hat CloudForms 4.7 and 5 that allows for Server-Side Request Forgery (SSRF) attacks.
How does CVE-2020-14296 work?
CVE-2020-14296 allows an attacker to scan and attack systems from the internal network which are not normally accessible by exploiting a Server-Side Request Forgery (SSRF) flaw through the addition of an Ansible Tower provider.
What is the severity of CVE-2020-14296?
The severity of CVE-2020-14296 is high, with a CVSSv3 severity score of 7.1.
How can I fix CVE-2020-14296?
To fix CVE-2020-14296, upgrade to Red Hat CloudForms version 5.11.7.0 or later.
Where can I find more information about CVE-2020-14296?
You can find more information about CVE-2020-14296 at the following references: [Red Hat Security Advisory RHSA-2020:3358](https://access.redhat.com/errata/RHSA-2020:3358), [Red Hat CVE-2020-14296](https://access.redhat.com/security/cve/cve-2020-14296), [Red Hat Bugzilla Bug 1847860](https://bugzilla.redhat.com/show_bug.cgi?id=1847860).