Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1353722 - (CVE-2016-5383) CVE-2016-5383 CloudForms: Lack of field filters on user input
CVE-2016-5383 CloudForms: Lack of field filters on user input
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20160818,repo...
: Security
Depends On: 1357072 1365674
Blocks: 1353727
  Show dependency treegraph
 
Reported: 2016-07-07 16:02 EDT by Kurt Seifried
Modified: 2016-09-10 23:25 EDT (History)
17 users (show)

See Also:
Fixed In Version: cfme 5.6.1.2
Doc Type: If docs needed, set a value
Doc Text:
It was found that the CloudForms web UI did not properly filter input in certain fields. A remote, authenticated attacker could use this flaw to execute arbitrary code on the system running CloudForms.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-09-10 23:25:33 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2016:1634 normal SHIPPED_LIVE Important: CFME 5.6.1 security, bug fix, and enhancement update 2016-08-18 17:43:52 EDT

  None (edit)
Description Kurt Seifried 2016-07-07 16:02:51 EDT
Eric Hayes of Red Hat reports:

A filter validation flaw exists in CloudForms, this could result in an attacker 
injecting content that then triggers code execution within CloudForms.
Comment 1 Kurt Seifried 2016-07-07 16:03:00 EDT
Acknowledgments:

Name: Eric Hayes (Red Hat)
Comment 4 errata-xmlrpc 2016-08-18 14:03:00 EDT
This issue has been addressed in the following products:

  CloudForms Management Engine 5.6

Via RHSA-2016:1634 https://rhn.redhat.com/errata/RHSA-2016-1634.html

Note You need to log in before you can comment on or make changes to this bug.