CVE Vulnerabilities

CVE-2020-10783

Published: Aug 11, 2020 | Modified: Jul 21, 2021
CVSS 3.x
8.3
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8.4 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Ubuntu

Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group can perform actions restricted only to EVM-Super-administrator group, leads to, exporting or importing administrator files.

Affected Software

Name Vendor Start Version End Version
Cloudforms Redhat 4.7 (including) 4.7 (including)
Cloudforms Redhat 5.0.0 (including) 5.0.0 (including)
CloudForms Management Engine 5.10 RedHat cfme-gemset-0:5.10.16.0-1.el7cf *
CloudForms Management Engine 5.11 RedHat cfme-gemset-0:5.11.7.3-1.el8cf *

References