Redhat Cloudforms Management Engine vulnerabilities
42 known vulnerabilities affecting redhat/cloudforms_management_engine.
Total CVEs
42
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH15MEDIUM21LOW3
Vulnerabilities
Page 2 of 3
CVE-2017-2653P4MEDIUMCVSS 6.5fixed in 5.7.2.12018-07-27
CVE-2017-2653 [MEDIUM] CWE-20 CVE-2017-2653: A number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via
A number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead of just POST requests. This could allow an attacker to bypass the protect_from_forgery XSRF protection causing the routes to be used. This attack would require additional cross-site scripting or similar attacks in order to execute.
nvd
CVE-2020-10780P4MEDIUMCVSS 6.3v4.7v5.0+1 more2020-08-11
CVE-2020-10780 [MEDIUM] CWE-1236 CVE-2020-10780: Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till
Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering any number of possible events. While this is strictly not an flaw that affects the application directly, attackers could use the l
nvd
CVE-2013-6461P4MEDIUMCVSS 6.5v5.02019-11-05
CVE-2013-6461 [MEDIUM] CWE-776 CVE-2013-6461: Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
nvd
CVE-2013-6460P4MEDIUMCVSS 6.5v5.02019-11-05
CVE-2013-6460 [MEDIUM] CWE-776 CVE-2013-6460: Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
nvd
CVE-2019-10177P4MEDIUMCVSS 6.5v5.9v5.102019-06-27
CVE-2019-10177 [MEDIUM] CWE-79 CVE-2019-10177: A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForm
A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is not properly sanitized. An attacker with least privilege to edit compute is able to execute a XSS attack against other users, which could lead to malicious code execution and extraction of the anti-CSRF to
nvd
CVE-2017-7528P4MEDIUMCVSS 6.5v5.02018-08-22
CVE-2017-7528 [MEDIUM] CWE-113 CVE-2017-7528: Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection
Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows internal servers to deploy other systems (using callback).
nvd
CVE-2019-14905P4MEDIUMCVSS 5.6v5.02020-03-31
CVE-2019-14905 [MEDIUM] CWE-20 CVE-2019-14905: A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x b
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of con
nvd
CVE-2017-15123P4MEDIUMCVSS 5.3≥ 5.8, ≤ 5.102019-06-12
CVE-2017-15123 [MEDIUM] CWE-306 CVE-2017-15123: A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are n
A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created virtual machines.
nvd
CVE-2016-3702P4MEDIUMCVSS 5.3v5.02017-04-21
CVE-2016-3702 [MEDIUM] CWE-200 CVE-2016-3702: Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain s
Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information.
nvd
CVE-2017-15125P4MEDIUMCVSS 5.4fixed in 5.9.0.222018-07-27
CVE-2017-15125 [MEDIUM] CWE-79 CVE-2017-15125: A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the nam
A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and JavaScript input. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms. Please note that CSP (Content Security Policy) prevents exploitation of th
nvd
CVE-2017-2632P4MEDIUMCVSS 4.9fixed in 5.7.1.32018-07-27
CVE-2017-2632 [MEDIUM] CWE-285 CVE-2017-2632: A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant admi
A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an attacker with tenant administration access to elevate privileges.
nvd
CVE-2018-10854P4MEDIUMCVSS 5.4v4.7v5.8+1 more2019-11-22
CVE-2018-10854 [MEDIUM] CWE-79 CVE-2018-10854: cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A fl
cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure mapping delete feature. A stored cross-site scripting due to improper sanitization of user input in Name field.
nvd
CVE-2016-7047P4MEDIUMCVSS 4.3≥ 5.6, < 5.6.3.0≥ 5.7, < 5.7.3.1+1 more2018-09-11
CVE-2016-7047 [MEDIUM] CWE-200 CVE-2016-7047: A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions
A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.
nvd
CVE-2020-1733P4MEDIUMCVSS 5.0v5.02020-03-11
CVE-2020-1733 [MEDIUM] CWE-377 CVE-2020-1733: A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior
A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 && mkdir -p "; this operation does not fail if the d
nvd
CVE-2014-3536P4MEDIUMCVSS 5.5v5.02019-12-15
CVE-2014-3536 [MEDIUM] CWE-532 CVE-2014-3536: CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during re
CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration
nvd
CVE-2015-7502P4MEDIUMCVSS 5.1v5.4.4v5.5.02016-04-11
CVE-2015-7502 [MEDIUM] CWE-200 CVE-2015-7502: Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.
Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend PostgreSQL database, which might allow local users to obtain sensitive data and consequently gain privileges by leveraging access to (1) database exports or (2) log files.
nvd
CVE-2020-1740P4MEDIUMCVSS 4.7v5.02020-03-16
CVE-2020-1740 [MEDIUM] CWE-377 CVE-2020-1740: A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing sec
nvd
CVE-2017-7497P4MEDIUMCVSS 4.3v5.7.2v5.8.02018-07-27
CVE-2017-7497 [MEDIUM] CWE-284 CVE-2017-7497: The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants
The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.
nvd
CVE-2020-1735P4MEDIUMCVSS 4.6v5.02020-03-16
CVE-2020-1735 [MEDIUM] CWE-22 CVE-2020-1735: A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept th
A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
nvd
CVE-2020-1739P4LOWCVSS 3.9v5.02020-03-12
CVE-2020-1739 [LOW] CWE-200 CVE-2020-1739: A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password i
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.
nvd