First published: Fri Jul 10 2020(Updated: )
A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerability can be exploited by authenticated attacker while setuping conversion host through Infrastructure Migration Solution. This flaw allows attacker to execute arbitrary commands on CloudForms server.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cfme | <5.11.7.0 | 5.11.7.0 |
Redhat Cloudforms Management Engine | <5.11.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14324 is a high severity vulnerability found in all active versions of Red Hat CloudForms before 5.11.7.0.
The CVE-2020-14324 vulnerability can be exploited by an authenticated attacker while setting up conversion host through Infrastructure Migration Solution.
CVE-2020-14324 has a severity level of 9.1 (Critical).
All active versions of Red Hat CloudForms before 5.11.7.0 are affected by CVE-2020-14324.
To fix the CVE-2020-14324 vulnerability, update Red Hat CloudForms to version 5.11.7.0 or later.