Bug 1847794 (CVE-2020-10780)
Summary: | CVE-2020-10780 CloudForms: CSV Injection in Orchestration Templates | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Yadnyawalk Tale <ytale> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | akarol, dmetzger, gmccullo, gtanzill, jfrey, jhardy, obarenbo, roliveri, security-response-team, simaishi, smallamp |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | cfme 5.11.7.0 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in Orchestration Template of Red Hat CloudForms where a low privilege user could enter crafted CSV formulae. Successful exploitation will allow an attacker to execute arbitrary code with the privilege of currently logged in user of the system causing serious damage to the victim’s system.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2020-08-06 19:27:51 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1847796 | ||
Bug Blocks: | 1847787 |
Description
Yadnyawalk Tale
2020-06-17 04:58:54 UTC
Acknowledgments: Name: Purnachand Pulahari (IBM), Ranjit Kumar Singh (IBM) This issue has been addressed in the following products: CloudForms Management Engine 5.11 Via RHSA-2020:3358 https://access.redhat.com/errata/RHSA-2020:3358 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-10780 Red Hat CVSS explanation: PR:L => To download CSV from CloudForms Management Engine (CFME) attacker need user-level authentication. AV:N => The vulnerability is in the web application and reasonably requires network interaction with the server. I:L => If an attacker exploited CSV injection against users then it would be an integrity and availability breach of the user's machine and not of CloudForms server where the CloudForms Management Engine (CFME) is deployed and hosted. This CSV injection is only intended to work on Windows and not on Linux machines, CFME can be only installed on Linux systems. One more reason being, if an attacker is able to get exploit working against the admin of CFME he will be able to modify CloudForms Management Engine's data but not of CloudForms Server's since those are two different entities with separate authentication mechanisms. A:N => As mentioned above, CFME and Server are two different entities with separate authentication mechanisms, if an attacker gets admin access of CFME web application, it is assumed that he can not harm availability of CloudForms server. |