Skip to main content

Vendor/product archive

redhat / cloudforms CVEs

Beta · best-effort

48 CVEs tagged to redhat / cloudforms3 Critical, 21 High, 21 Medium, 3 Low, 0 Unrated.

CVE-2020-25716

Published Jun 7, 2021

A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a specific group can perform ac…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14369

Published Dec 2, 2020

This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a web application in which the…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14325

Published Aug 11, 2020

Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and non-existent role-based acces…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10783

Published Aug 11, 2020

Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group can perform actions restricted only to EVM-Super-administra…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10779

Published Aug 11, 2020

Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10778

Published Aug 11, 2020

In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side vali…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10777

Published Aug 11, 2020

A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application admi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10159

Published Jun 14, 2019

cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration log controller. An attacker with access…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12148

Published Jul 27, 2018

A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not have the 'delete before update'…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 48 CVEsPage 1 of 2