CVE-2017-7497

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
27/07/2018
Last modified:
17/06/2026

Description

The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:cloudforms_management_engine:5.7.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_management_engine:5.8.0:*:*:*:*:*:*:*