Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group can perform actions restricted only to EVM-Super-administrator group, leads to, exporting or importing administrator files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cloudforms | Redhat | 4.7 (including) | 4.7 (including) |
Cloudforms | Redhat | 5.0.0 (including) | 5.0.0 (including) |
CloudForms Management Engine 5.10 | RedHat | cfme-gemset-0:5.10.16.0-1.el7cf | * |
CloudForms Management Engine 5.11 | RedHat | cfme-gemset-0:5.11.7.3-1.el8cf | * |