Bug 1374215 (CVE-2016-7047) - CVE-2016-7047 cfme: API leaks any MiqReportResult
Summary: CVE-2016-7047 cfme: API leaks any MiqReportResult
Status: CLOSED ERRATA
Alias: CVE-2016-7047
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=low,public=20170628,reported=2...
Keywords: Reopened, Security
: 1441502 (view as bug list)
Depends On: 1374965 1376875 1376876 1450493
Blocks: 1374219 1435396
TreeView+ depends on / blocked
 
Reported: 2016-09-08 09:27 UTC by Adam Mariš
Modified: 2019-06-08 21:25 UTC (History)
19 users (show)

(edit)
A flaw was found in the CloudForms API. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.
Clone Of:
(edit)
Last Closed: 2017-08-02 19:11:57 UTC


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:1601 normal SHIPPED_LIVE Important: CFME 5.7.3 security, bug fix and enhancement update 2017-06-28 18:51:52 UTC
Red Hat Product Errata RHSA-2017:1758 normal SHIPPED_LIVE Important: Red Hat CloudForms security, bug fix, and enhancement update 2017-08-02 21:23:43 UTC

Description Adam Mariš 2016-09-08 09:27:44 UTC
It was found that The API leaks any MiqReportResult to user that has entitlement to this feature.

Comment 1 Adam Mariš 2016-09-08 09:27:58 UTC
Acknowledgments:

Name: Simon Lukasik (Red Hat)

Comment 5 Šimon Lukašík 2016-11-01 10:16:59 UTC
Scope is bigger than originally anticipated. Has several entry points. Affects UI as well.

Will fix everything in this bug. As it is all related to MiqReportResult leakage.

Comment 9 Libor Pichler 2017-04-13 09:07:06 UTC
*** Bug 1441502 has been marked as a duplicate of this bug. ***

Comment 10 Kurt Seifried 2017-04-20 20:33:04 UTC

*** This bug has been marked as a duplicate of bug 1435396 ***

Comment 11 Kurt Seifried 2017-04-20 20:35:39 UTC
Marked wrong bug as duplicate.

Comment 14 errata-xmlrpc 2017-06-28 15:05:53 UTC
This issue has been addressed in the following products:

  CloudForms Management Engine 5.7

Via RHSA-2017:1601 https://access.redhat.com/errata/RHSA-2017:1601

Comment 15 errata-xmlrpc 2017-08-02 17:35:17 UTC
This issue has been addressed in the following products:

  CloudForms Management Engine 5.8

Via RHSA-2017:1758 https://access.redhat.com/errata/RHSA-2017:1758


Note You need to log in before you can comment on or make changes to this bug.