Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2018-10854
Disclosure Date: November 22, 2019 (last updated November 27, 2024)
cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure mapping delete feature. A stored cross-site scripting due to improper sanitization of user input in Name field.
0
Attacker Value
Unknown
CVE-2017-7497
Disclosure Date: July 27, 2018 (last updated November 27, 2024)
The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.
0
Attacker Value
Unknown
CVE-2017-2639
Disclosure Date: July 27, 2018 (last updated November 27, 2024)
It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. This would allow an attacker to spoof RHEV or OpenShift systems and potentially harvest sensitive information from CloudForms.
0
Attacker Value
Unknown
CVE-2018-10905
Disclosure Date: July 24, 2018 (last updated November 27, 2024)
CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an unprivileged local shell could use this flaw to execute commands as a high privileged user.
0