Lucene search

K
redhatRedHatRHSA-2020:3574
HistoryAug 27, 2020 - 3:55 p.m.

(RHSA-2020:3574) Critical: CloudForms 4.7.16 security, bug fix and enhancement update

2020-08-2715:55:13
access.redhat.com
26

0.002 Low

EPSS

Percentile

55.2%

Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components.

Security Fix(es):

  • cfme: CloudForms: Out-of-band OS Command Injection through conversion host (CVE-2020-14324)

  • cfme-appliance: CloudForms: User Impersonation in the API for OIDC and SAML (CVE-2020-14325)

  • cfme-gemset: CloudForms: Business logic bypass through widgets (CVE-2020-10778)

  • cfme-gemset: CloudForms: Missing access control leads to escalation of admin group privileges (CVE-2020-10783)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

This update fixes various bugs and adds enhancements. Documentation for these changes is available from the Release Notes document linked to in the References section.

0.002 Low

EPSS

Percentile

55.2%