The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.
References
Link | Resource |
---|---|
https://access.redhat.com/errata/RHSA-2017:1601 | Vendor Advisory |
https://access.redhat.com/errata/RHSA-2017:1758 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7497 | Issue Tracking Patch Vendor Advisory |
https://access.redhat.com/errata/RHSA-2017:1601 | Vendor Advisory |
https://access.redhat.com/errata/RHSA-2017:1758 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7497 | Issue Tracking Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:32
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 4.0
v3 : 4.1 |
References | () https://access.redhat.com/errata/RHSA-2017:1601 - Vendor Advisory | |
References | () https://access.redhat.com/errata/RHSA-2017:1758 - Vendor Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7497 - Issue Tracking, Patch, Vendor Advisory |
Information
Published : 2018-07-27 15:29
Updated : 2024-11-21 03:32
NVD link : CVE-2017-7497
Mitre link : CVE-2017-7497
CVE.ORG link : CVE-2017-7497
JSON object : View
Products Affected
redhat
- cloudforms_management_engine
CWE