Improper Access Control in CloudForms Web Interface by Red Hat
CVE-2017-15123
5.3MEDIUM
Summary
A security flaw in the CloudForms web interface (versions 5.8 - 5.10) allows unauthorized users to access RSS feed URLs without proper authentication. This vulnerability could result in the exposure of sensitive information, including details about newly created virtual machines. Proper security measures should be implemented to prevent unauthorized access and protect sensitive data.
Affected Version(s)
CloudForms 5.8 - 5.10
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved