CVE-2020-10779
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/08/2020
Last modified:
21/07/2021
Description
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible to access some sensitive data within the CloudForms.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:redhat:cloudforms:4.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:cloudforms:5.0.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page