Bug 1374215 (CVE-2016-7047) - CVE-2016-7047 cfme: API leaks any MiqReportResult
Summary: CVE-2016-7047 cfme: API leaks any MiqReportResult
Alias: CVE-2016-7047
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
: 1441502 (view as bug list)
Depends On: 1374965 1376875 1376876 1450493
Blocks: 1374219 1435396
TreeView+ depends on / blocked
Reported: 2016-09-08 09:27 UTC by Adam Mariš
Modified: 2021-02-17 03:22 UTC (History)
19 users (show)

Fixed In Version: cfme, cfme, cfme
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the CloudForms API. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.
Clone Of:
Last Closed: 2017-08-02 19:11:57 UTC

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:1601 0 normal SHIPPED_LIVE Important: CFME 5.7.3 security, bug fix and enhancement update 2017-06-28 18:51:52 UTC
Red Hat Product Errata RHSA-2017:1758 0 normal SHIPPED_LIVE Important: Red Hat CloudForms security, bug fix, and enhancement update 2017-08-02 21:23:43 UTC

Description Adam Mariš 2016-09-08 09:27:44 UTC
It was found that The API leaks any MiqReportResult to user that has entitlement to this feature.

Comment 1 Adam Mariš 2016-09-08 09:27:58 UTC

Name: Simon Lukasik (Red Hat)

Comment 5 Šimon Lukašík 2016-11-01 10:16:59 UTC
Scope is bigger than originally anticipated. Has several entry points. Affects UI as well.

Will fix everything in this bug. As it is all related to MiqReportResult leakage.

Comment 9 Libor Pichler 2017-04-13 09:07:06 UTC
*** Bug 1441502 has been marked as a duplicate of this bug. ***

Comment 10 Kurt Seifried 2017-04-20 20:33:04 UTC

*** This bug has been marked as a duplicate of bug 1435396 ***

Comment 11 Kurt Seifried 2017-04-20 20:35:39 UTC
Marked wrong bug as duplicate.

Comment 14 errata-xmlrpc 2017-06-28 15:05:53 UTC
This issue has been addressed in the following products:

  CloudForms Management Engine 5.7

Via RHSA-2017:1601 https://access.redhat.com/errata/RHSA-2017:1601

Comment 15 errata-xmlrpc 2017-08-02 17:35:17 UTC
This issue has been addressed in the following products:

  CloudForms Management Engine 5.8

Via RHSA-2017:1758 https://access.redhat.com/errata/RHSA-2017:1758

Note You need to log in before you can comment on or make changes to this bug.