CVE-2020-25716: High severity red hat cloudforms vulnerability
A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a specific group can perform actions restricted only to system administrator. This is the affect of an incomplete fix for CVE-2020-10783. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before cfme 5.11.10.1 are affected
Other sources
Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with specific group can perform actions restricted only to EVM-Super-administrator group, leads to, exporting or importing administrator files. Initial patches of CVE-2020-10783 were later considered incomplete for other RBAC groups.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25716?
CVE-2020-25716 is a flaw in Cloudforms that allows role-based privileges escalation and export or import of administrator files.
What is the severity of CVE-2020-25716?
CVE-2020-25716 has a severity rating of 8.1 (high).
Which software is affected by CVE-2020-25716?
Red Hat Cloudforms version 5.11.10.1 and Red Hat CFME version 5.11.10.1 are affected by CVE-2020-25716.
How can an attacker exploit CVE-2020-25716?
An attacker with a specific group can perform actions restricted only to system administrators by exploiting CVE-2020-25716.
Where can I find more information about CVE-2020-25716?
You can find more information about CVE-2020-25716 on the Red Hat Bugzilla page (https://bugzilla.redhat.com/show_bug.cgi?id=1898525), the Red Hat Security Advisory (https://access.redhat.com/errata/RHSA-2020:5554), and the official CVE page (https://access.redhat.com/security/cve/CVE-2020-10783).