Red Hat Cloudforms vulnerabilities
5 known vulnerabilities affecting red_hat/cloudforms.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2018-10854MEDIUMCVSS 5.4vcloudforms 5.8 and cloudforms 5.92019-11-22
CVE-2018-10854 [MEDIUM] CWE-79 CVE-2018-10854: cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A fl
cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure mapping delete feature. A stored cross-site scripting due to improper sanitization of user input in Name field.
cvelistv5nvd
CVE-2019-10177MEDIUMCVSS 6.5v5.9, 5.102019-06-27
CVE-2019-10177 [MEDIUM] CWE-79 CVE-2019-10177: A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForm
A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is not properly sanitized. An attacker with least privilege to edit compute is able to execute a XSS attack against other users, which could lead to malicious code execution and extraction of the anti-CSRF to
cvelistv5nvd
CVE-2017-15125MEDIUMCVSS 5.4v5.9.0.222018-07-27
CVE-2017-15125 [MEDIUM] CWE-79 CVE-2017-15125: A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the nam
A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and JavaScript input. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms. Please note that CSP (Content Security Policy) prevents exploitation of th
cvelistv5nvd
CVE-2017-2653MEDIUMCVSS 6.5v5.7.2.12018-07-27
CVE-2017-2653 [MEDIUM] CWE-20 CVE-2017-2653: A number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via
A number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead of just POST requests. This could allow an attacker to bypass the protect_from_forgery XSRF protection causing the routes to be used. This attack would require additional cross-site scripting or similar attacks in order to execute.
cvelistv5nvd
CVE-2017-2664MEDIUMCVSS 6.5v5.7.3v5.8.12018-07-26
CVE-2017-2664 [MEDIUM] CWE-284 CVE-2017-2664: CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certa
CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within the rails application portion of CloudForms to escalate privileges.
cvelistv5nvd