CVE Vulnerabilities

CVE-2020-10778

Incorrect Resource Transfer Between Spheres

Published: Aug 11, 2020 | Modified: Nov 21, 2024
CVSS 3.x
6
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8.2 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavior.

Weakness

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Affected Software

NameVendorStart VersionEnd Version
CloudformsRedhat4.7 (including)4.7 (including)
CloudformsRedhat5.0.0 (including)5.0.0 (including)
CloudForms Management Engine 5.10RedHatcfme-gemset-0:5.10.16.0-1.el7cf*
CloudForms Management Engine 5.11RedHatcfme-gemset-0:5.11.7.3-1.el8cf*

References