CVEs (48)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a specific group can perform actions restricted only to system administr...Show more |
This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a web application in which the user is currently authenticated. An attac...Show more |
Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and non-existent role-based access control user, with groups and roles. Wi...Show more |
Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group can perform actions restricted only to EVM-Super-administrator group, leads to, exporting or importi...Show more |
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible...Show more |
In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate...Show more |
A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms. |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Dec 13, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 CFME: CSRF protection vulnerability via permissive check of the referrer header |
CloudForms stores user passwords in recoverable format |
1Redhat 2Cloudforms Manageiq Enterprise Virtualization ManagerNov 21, 2024 Nov 1, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
3Fedoraproject RedhatRubyzip Project3Cloudforms FedoraRubyzipJun 17, 2026 Sep 25, 2019 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). |
1Redhat 2Cfme Gemset CloudformsJun 17, 2026 Jun 14, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration log controller. An attacker with access to an unprivileged user can access all V...Show more |
11Backdropcms DebianDrupal+8 more105Agile Product Lifecycle Management For Process Application ExpressApplication Service Level Management+102 moreJun 17, 2026 Apr 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ p...Show more |
5Debian FedoraprojectOpensuse+2 more6Cloudforms Debian LinuxFedora+3 moreJun 17, 2026 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unre...Show more |
5Debian FedoraprojectOpensuse+2 more6Cloudforms Debian LinuxFedora+3 moreJun 17, 2026 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesyste...Show more |
2Redhat Rubyonrails2Cloudforms RailsNov 21, 2024 Nov 30, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they shoul...Show more |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Oct 31, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execut...Show more |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Sep 11, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which...Show more |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Sep 10, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems...Show more |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Jul 27, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an...Show more |