First published: Wed Jun 17 2020(Updated: )
Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not normally accessible.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Cloudforms Management Engine | =4.7 | |
Redhat Cloudforms Management Engine | =5.0 | |
redhat/cfme | <5.11.7.0 | 5.11.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14296 is a vulnerability in Red Hat CloudForms 4.7 and 5 that allows for Server-Side Request Forgery (SSRF) attacks.
CVE-2020-14296 allows an attacker to scan and attack systems from the internal network which are not normally accessible by exploiting a Server-Side Request Forgery (SSRF) flaw through the addition of an Ansible Tower provider.
The severity of CVE-2020-14296 is high, with a CVSSv3 severity score of 7.1.
To fix CVE-2020-14296, upgrade to Red Hat CloudForms version 5.11.7.0 or later.
You can find more information about CVE-2020-14296 at the following references: [Red Hat Security Advisory RHSA-2020:3358](https://access.redhat.com/errata/RHSA-2020:3358), [Red Hat CVE-2020-14296](https://access.redhat.com/security/cve/cve-2020-14296), [Red Hat Bugzilla Bug 1847860](https://bugzilla.redhat.com/show_bug.cgi?id=1847860).