CVE-2017-7530

In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing when invoking arbitrary methods via filtering on VMs that MiqExpression will execute that is triggerable by API users. An attacker could use this to execute actions they should not be allowed to (e.g. destroying VMs).
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7530 Issue Tracking Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:1758 Vendor Advisory
http://www.securityfocus.com/bid/100151 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:cloudforms_management_engine:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_management_engine:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms:4.5:*:*:*:*:*:*:*

Information

Published : 2018-07-26 06:29

Updated : 2019-10-09 16:29


NVD link : CVE-2017-7530

Mitre link : CVE-2017-7530


JSON object : View

Advertisement

dedicated server usa

Products Affected

redhat

  • cloudforms_management_engine
  • cloudforms