First published: Fri Jul 10 2020(Updated: )
Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and non-existent role-based access control user, with groups and roles. With a selected group of EvmGroup-super_administrator, an attacker can perform any API request as a super administrator.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cfme | <5.11.7.0 | 5.11.7.0 |
Redhat Cloudforms | <5.11.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Red Hat CloudForms vulnerability is CVE-2020-14325.
The severity of CVE-2020-14325 is critical with a CVSS score of 9.1.
The affected software for CVE-2020-14325 is Red Hat CloudForms version before 5.11.7.0.
An attacker can exploit CVE-2020-14325 by creating existent and non-existent role-based access control users with groups and roles, specifically using the group EvmGroup-super_administrator.
You can find more information about CVE-2020-14325 on the Red Hat Security Advisory and Bugzilla pages.