Lucene search

K
cvelistRedhatCVELIST:CVE-2020-25716
HistoryJun 07, 2021 - 8:27 p.m.

CVE-2020-25716

2021-06-0720:27:15
CWE-285
redhat
www.cve.org
2

8.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.8%

A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a specific group can perform actions restricted only to system administrator. This is the affect of an incomplete fix for CVE-2020-10783. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before cfme 5.11.10.1 are affected

CNA Affected

[
  {
    "product": "Cloudforms",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "before cfme 5.11.10.1"
      }
    ]
  }
]

8.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.8%