Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10779

Опубликовано: 03 авг. 2020
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible to access some sensitive data within the CloudForms.

A flaw was found in Red Hat CloudForms where sensitive data would have been possibly leaked for other existing roles. An attacker with low privilege could make use of EVM-Admin API if certain criteria is met since there was no privilege check on feature.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.

Дополнительная информация

Статус:

Important
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1847647CloudForms: Missing functional level access control & IDOR lead to compromise

EPSS

Процентиль: 40%
0.0018
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 5 лет назад

Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible to access some sensitive data within the CloudForms.

CVSS3: 7.6
fstec
больше 5 лет назад

Уязвимость программной платформы для управления виртуальными средами CloudForms Management Engine, связанная с недостатками контроля доступа, позволяющая нарушителю получить доступ к некоторым конфиденциальным данным в CloudForms

EPSS

Процентиль: 40%
0.0018
Низкий

7.6 High

CVSS3