Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25716

Опубликовано: 17 нояб. 2020
Источник: redhat
CVSS3: 8.4
EPSS Низкий

Описание

A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a specific group can perform actions restricted only to system administrator. This is the affect of an incomplete fix for CVE-2020-10783. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before cfme 5.11.10.1 are affected

A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a specific group can perform actions restricted only to system administrator. This is the affect of an incomplete fix for CVE-2020-10783. The highest threat from this vulnerability is to data confidentiality and integrity.

Отчет

This vulnerability stems from incomplete fixes for a previously disclosed CVE-2020-10783, which only fixed this flaw for EVM-Operator group.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.

Дополнительная информация

Статус:

Important
Дефект:
CWE-285->CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1898525Cloudforms: Incomplete fix for CVE-2020-10783

EPSS

Процентиль: 37%
0.00157
Низкий

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
больше 4 лет назад

A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a specific group can perform actions restricted only to system administrator. This is the affect of an incomplete fix for CVE-2020-10783. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before cfme 5.11.10.1 are affected

EPSS

Процентиль: 37%
0.00157
Низкий

8.4 High

CVSS3

Уязвимость CVE-2020-25716