CVE-2020-14324

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
11/08/2020
Last modified:
13/08/2020

Description

A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerability can be exploited by authenticated attacker while setuping conversion host through Infrastructure Migration Solution. This flaw allows attacker to execute arbitrary commands on CloudForms server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:cloudforms_management_engine:*:*:*:*:*:*:*:* 5.11.7.0 (excluding)