Redhat
Redhat Cloudforms: vulnerabilidades y CVE
Redhat Cloudforms tiene 48 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE48
Últimos 12 meses0
Críticas3
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-5418 | Alta (7.5) | 99% | ⚠ Explotación activa | 27 mar 2019 | There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-25716 | Alta (8.1) | 0.77% | — | 7 jun 2021 | A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a specific group can perform actions restricted only to system… |
| CVE-2020-14369 | Media (6.3) | 0.34% | — | 2 dic 2020 | This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a web application in which the user is currently authenticated. An… |
| CVE-2020-14325 | Crítica (9.1) | 1.1% | — | 11 ago 2020 | Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and non-existent role-based access control user, with groups and roles.… |
| CVE-2020-10783 | Alta (8.3) | 1.0% | — | 11 ago 2020 | Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group can perform actions restricted only to EVM-Super-administrator group, leads to, exporting or… |
| CVE-2020-10779 | Media (6.5) | 0.78% | — | 11 ago 2020 | Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is… |
| CVE-2020-10778 | Media (6) | 0.88% | — | 11 ago 2020 | In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate… |
| CVE-2020-10777 | Media (5.4) | 0.66% | — | 11 ago 2020 | A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms. |
| CVE-2014-0197 | Alta (8.8) | 0.68% | — | 13 dic 2019 | CFME: CSRF protection vulnerability via permissive check of the referrer header |
| CVE-2013-4423 | Media (5.5) | 0.31% | — | 4 nov 2019 | CloudForms stores user passwords in recoverable format |
| CVE-2013-0186 | Media (6.1) | 0.91% | — | 1 nov 2019 | Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2019-16892 | Media (5.5) | 1.6% | — | 25 sept 2019 | In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). |
| CVE-2019-10159 | Media (4.3) | 0.72% | — | 14 jun 2019 | cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration log controller. An attacker with access to an unprivileged user can access all… |
| CVE-2019-11358 | Media (6.1) | 87% | — | 20 abr 2019 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__… |
| CVE-2019-5419 | Alta (7.5) | 8.8% | — | 27 mar 2019 | There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server… |
| CVE-2019-5418 | Alta (7.5) | 99% | ⚠ Explotación activa | 27 mar 2019 | There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's… |
| CVE-2018-16476 | Alta (7.5) | 2.6% | — | 30 nov 2018 | A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they… |
| CVE-2016-5402 | Alta (8.8) | 5.9% | — | 31 oct 2018 | A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to… |
| CVE-2016-7047 | Media (4.3) | 1.3% | — | 11 sept 2018 | A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which… |
| CVE-2016-7071 | Alta (8.8) | 2.2% | — | 10 sept 2018 | It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on… |
| CVE-2017-2632 | Media (4.9) | 1.5% | — | 27 jul 2018 | A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an… |
| CVE-2017-2653 | Media (6.5) | 1.4% | — | 27 jul 2018 | A number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead of just POST requests. This could allow an attacker to bypass the protect_from_forgery XSRF… |
| CVE-2017-12148 | Alta (7.2) | 1.7% | — | 27 jul 2018 | A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not have the 'delete before update' flag set, an attacker with commit… |
| CVE-2017-2639 | Alta (7.5) | 1.1% | — | 27 jul 2018 | It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. This would… |
| CVE-2017-2664 | Media (6.5) | 1.3% | — | 26 jul 2018 | CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods… |
| CVE-2017-7530 | Alta (8.8) | 1.7% | — | 26 jul 2018 | In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing when invoking arbitrary methods via filtering on VMs that MiqExpression will execute that is… |
| CVE-2018-10905 | Alta (7.8) | 0.47% | — | 24 jul 2018 | CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an unprivileged local shell could use this flaw to execute commands as a… |
| CVE-2018-10855 | Media (5.9) | 3.1% | — | 3 jul 2018 | Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does… |
| CVE-2018-3760 | Alta (7.5) | 27% | — | 26 jun 2018 | There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem… |
| CVE-2018-1000544 | Crítica (9.8) | 4.4% | — | 26 jun 2018 | rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a… |
| CVE-2018-11627 | Media (6.1) | 2.2% | — | 31 may 2018 | Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 238Linux · 230