Bug 1847811 (CVE-2020-10783)
| Summary: | CVE-2020-10783 CloudForms: Missing access control leads to escalation of admin group privileges | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Yadnyawalk Tale <ytale> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | akarol, dmetzger, gmccullo, gtanzill, jfrey, jhardy, obarenbo, roliveri, security-response-team, simaishi, smallamp |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | cfme-gemset 5.11.7.1 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A role-based privileges escalation flaw was found in Red Hat CloudForms where export or import of administrator files was possible. An attacker with EVM-Operator group can perform actions restricted only to system administrator.
Refer CVE-2020-25716 for remaining RBAC group fixes.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2020-08-06 19:27:54 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1847816, 1847817 | ||
| Bug Blocks: | 1847798 | ||
|
Description
Yadnyawalk Tale
2020-06-17 06:15:43 UTC
Acknowledgments: Name: Purnachand Pulahari (IBM), Ranjit Kumar Singh (IBM) Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. This issue has been addressed in the following products: CloudForms Management Engine 5.11 Via RHSA-2020:3358 https://access.redhat.com/errata/RHSA-2020:3358 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-10783 This issue has been addressed in the following products: CloudForms Management Engine 5.10 Via RHSA-2020:3574 https://access.redhat.com/errata/RHSA-2020:3574 |