Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible to access some sensitive data within the CloudForms.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2020-08-11T12:40:35

Updated: 2020-08-11T12:40:35

Reserved: 2020-03-20T00:00:00


Link: CVE-2020-10779

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-08-11T13:15:12.087

Modified: 2021-07-21T11:39:23.747


Link: CVE-2020-10779

JSON object: View

cve-icon Redhat Information

No data.

CWE