CVE-2020-10778

In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavior.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:cloudforms:4.7:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms:5.0.0:*:*:*:*:*:*:*

History

21 Nov 2024, 04:56

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/cve-2020-10778 - Vendor Advisory () https://access.redhat.com/security/cve/cve-2020-10778 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=1847628 - Issue Tracking, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1847628 - Issue Tracking, Vendor Advisory

Information

Published : 2020-08-11 13:15

Updated : 2024-11-21 04:56


NVD link : CVE-2020-10778

Mitre link : CVE-2020-10778

CVE.ORG link : CVE-2020-10778


JSON object : View

Products Affected

redhat

  • cloudforms
CWE
CWE-669

Incorrect Resource Transfer Between Spheres