CVE Vulnerabilities

CVE-2020-25716

Published: Jun 07, 2021 | Modified: Nov 07, 2023
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
8.4 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Ubuntu

A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a specific group can perform actions restricted only to system administrator. This is the affect of an incomplete fix for CVE-2020-10783. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before cfme 5.11.10.1 are affected

Affected Software

Name Vendor Start Version End Version
Cloudforms Redhat * 5.11.10.1 (excluding)
CloudForms Management Engine 5.11 RedHat cfme-0:5.11.10.1-1.el8cf *
CloudForms Management Engine 5.11 RedHat cfme-amazon-smartstate-0:5.11.10.1-1.el8cf *
CloudForms Management Engine 5.11 RedHat cfme-appliance-0:5.11.10.1-1.el8cf *
CloudForms Management Engine 5.11 RedHat cfme-gemset-0:5.11.10.1-1.el8cf *
CloudForms Management Engine 5.11 RedHat v2v-conversion-host-0:1.16.2-6.el8ev *

References