Redhat Cloudforms vulnerabilities
49 known vulnerabilities affecting redhat/cloudforms.
Total CVEs
49
CISA KEV
1
actively exploited
Public exploits
5
Exploited in wild
4
Severity breakdown
CRITICAL3HIGH22MEDIUM21LOW3
Vulnerabilities
Page 3 of 3
CVE-2016-7047P4MEDIUMCVSS 4.3v4.2v4.52018-09-11
CVE-2016-7047 [MEDIUM] CWE-200 CVE-2016-7047: A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions
A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.
nvd
CVE-2014-0081P4MEDIUMCVSS 4.3v3.02014-02-20
CVE-2014-0081 [MEDIUM] CWE-79 CVE-2014-0081: Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_hel
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to the (a) number_to_currency, (b) numbe
nvd
CVE-2013-4423P4MEDIUMCVSS 5.5v3.02019-11-04
CVE-2013-4423 [MEDIUM] CWE-522 CVE-2013-4423: CloudForms stores user passwords in recoverable format
CloudForms stores user passwords in recoverable format
nvd
CVE-2015-7502P4MEDIUMCVSS 5.1v3.2v4.02016-04-11
CVE-2015-7502 [MEDIUM] CWE-200 CVE-2015-7502: Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.
Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend PostgreSQL database, which might allow local users to obtain sensitive data and consequently gain privileges by leveraging access to (1) database exports or (2) log files.
nvd
CVE-2019-10159P4MEDIUMCVSS 4.3v4.72019-06-14
CVE-2019-10159 [MEDIUM] CWE-285 CVE-2019-10159: cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an
cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration log controller. An attacker with access to an unprivileged user can access all VM migration logs available.
nvd
CVE-2019-16892P4MEDIUMCVSS 5.5v4.7v5.112019-09-25
CVE-2019-16892 [MEDIUM] CVE-2019-16892: In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
nvd
CVE-2012-3538P4LOWCVSS 3.3≤ 1.02013-01-04
CVE-2012-3538 [LOW] CWE-255 CVE-2012-3538: Pulp in Red Hat CloudForms before 1.1 logs administrative passwords in a world-readable file, which
Pulp in Red Hat CloudForms before 1.1 logs administrative passwords in a world-readable file, which allows local users to read pulp administrative passwords by reading production.log.
nvd
CVE-2012-4574P4LOWCVSS 2.1≤ 1.02013-01-04
CVE-2012-4574 [LOW] CWE-255 CVE-2012-4574: Pulp in Red Hat CloudForms before 1.1 uses world-readable permissions for pulp.conf, which allows lo
Pulp in Red Hat CloudForms before 1.1 uses world-readable permissions for pulp.conf, which allows local users to read the administrative password by reading this file.
nvd
CVE-2012-5605P4LOWCVSS 2.1≤ 1.02013-01-04
CVE-2012-5605 [LOW] CWE-264 CVE-2012-5605: Grinder in Red Hat CloudForms before 1.1 uses world-writable permissions for /var/lib/pulp/cache/gri
Grinder in Red Hat CloudForms before 1.1 uses world-writable permissions for /var/lib/pulp/cache/grinder/, which allows local users to modify grinder cache files.
nvd
← Previous3 / 3