Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and non-existent role-based access control user, with groups and roles. With a selected group of EvmGroup-super_administrator, an attacker can perform any API request as a super administrator.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cloudforms | Redhat | * | 5.11.7.0 (excluding) |
CloudForms Management Engine 5.10 | RedHat | cfme-appliance-0:5.10.16.0-1.el7cf | * |
CloudForms Management Engine 5.11 | RedHat | cfme-0:5.11.7.3-1.el8cf | * |