Bug 1524720 (CVE-2017-15123)

Summary: CVE-2017-15123 CloudForms: RSS links are accessible without any authentication
Product: [Other] Security Response Reporter: Kurt Seifried <kseifried>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: akarol, cpelland, dajohnso, dmetzger, gblomqui, gmccullo, gtanzill, hhudgeon, jfrey, jhardy, jprause, kdixon, mrehak, obarenbo, roliveri, security-response-team, simaishi, smallamp
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the CloudForms web interface where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created virtual machines.
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-05 20:31:08 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1518946, 1536089, 1536090, 1536536, 1717531    
Bug Blocks: 1524458    

Description Kurt Seifried 2017-12-11 21:59:42 UTC
Pete Savage of Red Hat reports:

It was found that RSS links are accessible without any authentication in CFME.

Comment 1 Kurt Seifried 2018-01-12 20:47:37 UTC
Acknowledgments:

Name: Pete Savage (Red Hat)

Comment 9 Richard Maciel Costa 2019-06-05 20:30:26 UTC
Statement:

Red Hat Product Security has rated this issue as having a moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.