Libor Pichler and Martin Povolny report: Cloudforms lacks RBAC controls on a variety of methods potentially allowing authenticated users to escalate privileges and use methods they should not have access to.
Acknowledgments: Name: Libor Pichler (Red Hat), Martin Povolny (Red Hat)
*** Bug 1434771 has been marked as a duplicate of this bug. ***
This issue has been addressed in the following products: CloudForms Management Engine 5.8 Via RHSA-2017:1758 https://access.redhat.com/errata/RHSA-2017:1758
This issue has been addressed in the following products: CloudForms Management Engine 5.7 Via RHSA-2017:3484 https://access.redhat.com/errata/RHSA-2017:3484