Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible to access some sensitive data within the CloudForms.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1847647 | Issue Tracking |
https://access.redhat.com/security/cve/cve-2020-10779 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-08-11 06:15
Updated : 2021-07-21 04:39
NVD link : CVE-2020-10779
Mitre link : CVE-2020-10779
JSON object : View
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
Products Affected
redhat
- cloudforms