Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:18127
HistoryMay 02, 2019 - 6:28 a.m.

Remote Code Execution

2019-05-0206:28:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.001 Low

EPSS

Percentile

30.0%

Red Hat CloudForms is vulnerable to remote code execution. This is because the dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.

References

0.001 Low

EPSS

Percentile

30.0%

Related for VERACODE:18127