Bug 1374215 (CVE-2016-7047)
Summary: | CVE-2016-7047 cfme: API leaks any MiqReportResult | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Adam Mariš <amaris> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | cpelland, dajohnso, dclarizi, gblomqui, gmccullo, gtanzill, hhudgeon, jfrey, jhardy, jprause, jrafanie, kseifried, lpichler, obarenbo, roliveri, security-response-team, simaishi, slong, slukasik |
Target Milestone: | --- | Keywords: | Reopened, Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | cfme 5.8.1.2, cfme 5.7.3.1, cfme 5.6.3.0 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in the CloudForms API. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2017-08-02 19:11:57 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1374965, 1376875, 1376876, 1450493 | ||
Bug Blocks: | 1374219, 1435396 |
Description
Adam Mariš
2016-09-08 09:27:44 UTC
Acknowledgments: Name: Simon Lukasik (Red Hat) Scope is bigger than originally anticipated. Has several entry points. Affects UI as well. Will fix everything in this bug. As it is all related to MiqReportResult leakage. *** Bug 1441502 has been marked as a duplicate of this bug. *** *** This bug has been marked as a duplicate of bug 1435396 *** Marked wrong bug as duplicate. This issue has been addressed in the following products: CloudForms Management Engine 5.7 Via RHSA-2017:1601 https://access.redhat.com/errata/RHSA-2017:1601 This issue has been addressed in the following products: CloudForms Management Engine 5.8 Via RHSA-2017:1758 https://access.redhat.com/errata/RHSA-2017:1758 |