A high severity vulnerability was found in all active versions of Red Hat CloudForms. The out of band OS command injection vulnerability can be exploited by authenticated attacker while setuping conversion host through Infrastructure Migration Solution. This flaw allows attacker to execute arbitrary commands on CloudForms server.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Acknowledgments: Name: Sruthi M (IBM), Pravat Kumar Sahoo (IBM)
This issue has been addressed in the following products: CloudForms Management Engine 5.11 Via RHSA-2020:3358 https://access.redhat.com/errata/RHSA-2020:3358
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-14324
This issue has been addressed in the following products: CloudForms Management Engine 5.10 Via RHSA-2020:3574 https://access.redhat.com/errata/RHSA-2020:3574