Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-82ph-q482-5fhg

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems managed by CloudForms if they know the ID of the VM.

It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems managed by CloudForms if they know the ID of the VM.

EPSS

Процентиль: 65%
0.00496
Низкий

8.8 High

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 8.8
redhat
больше 9 лет назад

It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems managed by CloudForms if they know the ID of the VM.

CVSS3: 8.8
nvd
больше 7 лет назад

It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems managed by CloudForms if they know the ID of the VM.

EPSS

Процентиль: 65%
0.00496
Низкий

8.8 High

CVSS3

Дефекты

CWE-285