Red Hat Bugzilla – Bug 1435393
CVE-2017-2664 CloudForms: lack of RBAC on various methods in web UI
Last modified: 2018-07-26 07:55:46 EDT
Libor Pichler and Martin Povolny report: Cloudforms lacks RBAC controls on a variety of methods potentially allowing authenticated users to escalate privileges and use methods they should not have access to.
Acknowledgments: Name: Libor Pichler (Red Hat), Martin Povolny (Red Hat)
*** Bug 1434771 has been marked as a duplicate of this bug. ***
This issue has been addressed in the following products: CloudForms Management Engine 5.8 Via RHSA-2017:1758 https://access.redhat.com/errata/RHSA-2017:1758
This issue has been addressed in the following products: CloudForms Management Engine 5.7 Via RHSA-2017:3484 https://access.redhat.com/errata/RHSA-2017:3484