Severity
6.3MEDIUM
EPSS
0.4%
top 39.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 11

Description

Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering any number of possible events. While this is strictly not an flaw that affects the application directly, attackers could use the loosely validated parameters to trigger several attack possibilities.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:NExploitability: 2.1 | Impact: 4.2

Affected Packages2 packages

CVEListV5cloudforms4.7 and 5

🔴Vulnerability Details

1
CVEList
CVE-2020-10780: Red Hat CloudForms 42020-08-11

📋Vendor Advisories

2
Red Hat
CloudForms: CSV Injection in Orchestration Templates2020-08-03
Red Hat
kernel: out-of-bounds read/write in the bpf verifier2020-03-30

💬Community

1
Bugzilla
CVE-2020-10780 CloudForms: CSV Injection in Orchestration Templates2020-06-17