Bug 1847794 (CVE-2020-10780) - CVE-2020-10780 CloudForms: CSV Injection in Orchestration Templates
Summary: CVE-2020-10780 CloudForms: CSV Injection in Orchestration Templates
Alias: CVE-2020-10780
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 1847796
Blocks: 1847787
TreeView+ depends on / blocked
Reported: 2020-06-17 04:58 UTC by Yadnyawalk Tale
Modified: 2021-02-16 19:53 UTC (History)
11 users (show)

Fixed In Version: cfme
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Orchestration Template of Red Hat CloudForms where a low privilege user could enter crafted CSV formulae. Successful exploitation will allow an attacker to execute arbitrary code with the privilege of currently logged in user of the system causing serious damage to the victim’s system.
Clone Of:
Last Closed: 2020-08-06 19:27:51 UTC

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2020:3358 0 None None None 2020-08-06 14:32:43 UTC

Description Yadnyawalk Tale 2020-06-17 04:58:54 UTC
Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering any number of possible events. While this is strictly not an flaw that affects the application directly, attackers could use the loosely validated parameters to trigger several attack possibilities.

Comment 4 Yadnyawalk Tale 2020-06-24 17:28:17 UTC

Name: Purnachand Pulahari (IBM), Ranjit Kumar Singh (IBM)

Comment 6 errata-xmlrpc 2020-08-06 14:32:41 UTC
This issue has been addressed in the following products:

  CloudForms Management Engine 5.11

Via RHSA-2020:3358 https://access.redhat.com/errata/RHSA-2020:3358

Comment 7 Product Security DevOps Team 2020-08-06 19:27:51 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):


Comment 8 Yadnyawalk Tale 2020-08-27 05:47:35 UTC
Red Hat CVSS explanation:

PR:L => To download CSV from CloudForms Management Engine (CFME) attacker need user-level authentication.
AV:N => The vulnerability is in the web application and reasonably requires network interaction with the server.
I:L => If an attacker exploited CSV injection against users then it would be an integrity and availability breach of the user's machine and not of CloudForms server where the CloudForms Management Engine (CFME) is deployed and hosted. This CSV injection is only intended to work on Windows and not on Linux machines, CFME can be only installed on Linux systems. One more reason being, if an attacker is able to get exploit working against the admin of CFME he will be able to modify CloudForms Management Engine's data but not of CloudForms Server's since those are two different entities with separate authentication mechanisms.
A:N => As mentioned above, CFME and Server are two different entities with separate authentication mechanisms, if an attacker gets admin access of CFME web application, it is assumed that he can not harm availability of CloudForms server.

Note You need to log in before you can comment on or make changes to this bug.