CVE-2020-14296 — Server-Side Request Forgery in Redhat Cloudforms
Severity
7.1HIGHNVD
EPSS
0.2%
top 64.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 11
Description
Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not normally accessible.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:NExploitability: 2.8 | Impact: 4.2
Affected Packages3 packages
🔴Vulnerability Details
1📋Vendor Advisories
1💬Community
1Bugzilla
▶