CVE-2020-14296Server-Side Request Forgery in Redhat Cloudforms

Severity
7.1HIGHNVD
EPSS
0.2%
top 64.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 11

Description

Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not normally accessible.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:NExploitability: 2.8 | Impact: 4.2

Affected Packages3 packages

CVEListV5redhat/cloudforms4.7 and 5

🔴Vulnerability Details

1
CVEList
CVE-2020-14296: Red Hat CloudForms 42020-08-11

📋Vendor Advisories

1
Red Hat
CloudForms: Server-Side Request Forgery (SSRF) in Ansible Tower Provider2020-08-03

💬Community

1
Bugzilla
CVE-2020-14296 CloudForms: Server-Side Request Forgery (SSRF) in Ansible Tower Provider2020-06-17