CVE-2017-15123
published 2019-06-12CVE-2017-15123: A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An…
PriorityP427medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
1.43%
70.3th percentile
A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created virtual machines.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | cloudforms | — | — |
| redhat | cloudforms_management_engine | 5.8 – 5.10 | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
CloudForms: RSS links are accessible without any authentication
vendor_redhat·2019-06-05·CVSS 5.3
CVE-2017-15123 [MEDIUM] CWE-306 CloudForms: RSS links are accessible without any authentication
CloudForms: RSS links are accessible without any authentication
A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created virtual machines.
A flaw was found in the CloudForms web interface where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created virtual machines.
Statement: Red Hat Product Security has rated this issue as having a moderate security impact. This issue is not currently planned to be addressed in future upda
GHSA
GHSA-9j5r-6jgc-rgpx: A flaw was found in the CloudForms web interface, versions 5
ghsa_unreviewed·2022-05-24
CVE-2017-15123 [MEDIUM] CWE-306 GHSA-9j5r-6jgc-rgpx: A flaw was found in the CloudForms web interface, versions 5
A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created virtual machines.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/108690https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15123https://hacked0x90.wordpress.com/2019/07/17/cve-2017-15123-exploit/http://www.securityfocus.com/bid/108690https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15123https://hacked0x90.wordpress.com/2019/07/17/cve-2017-15123-exploit/
2019-06-12
Published