Red Hat / Cloudforms
50 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-25716 | Cloudforms: Incomplete fix for CVE-2020-10783 | HIGH | 8.4 | Jun 7, 2021 |
| CVE-2020-14369 | CloudForms: Cross Site Request Forgery in API notifications | MEDIUM | 6.3 | Dec 2, 2020 |
| CVE-2020-14325 | CloudForms: User Impersonation in the API for OIDC and SAML | CRITICAL | 9.9 | Aug 11, 2020 |
| CVE-2020-10779 | CloudForms: Missing functional level access control & IDOR lead to compromise | HIGH | 7.6 | Aug 11, 2020 |
| CVE-2020-10783 | CloudForms: Missing access control leads to escalation of admin group privileges | HIGH | 8.4 | Aug 11, 2020 |
| CVE-2020-10778 | CloudForms: Business logic bypass through widgets | HIGH | 8.2 | Aug 11, 2020 |
| CVE-2020-10777 | CloudForms: Cross Site Scripting in report menu title / HTML Code Injection | MEDIUM | 6.5 | Aug 11, 2020 |
| CVE-2014-0197 | CFME: CSRF protection vulnerability in referrer header | HIGH | 8.8 | Dec 13, 2019 |
| CVE-2018-10854 | cloudforms: stored cross-site scripting in Name field | MEDIUM | 5.4 | Nov 22, 2019 |
| CVE-2013-4423 | CloudForms: user password stored in recoverable format | MEDIUM | 5.5 | Nov 4, 2019 |
| CVE-2013-0186 | EVM: Stored XSS | MEDIUM | 6.1 | Nov 1, 2019 |
| CVE-2019-16892 | cfme: rubygem-rubyzip denial of service via crafted ZIP file | MEDIUM | 5.5 | Sep 25, 2019 |
| CVE-2019-10177 | CloudForms: Store XSS in PDF exports feature allows code execution of Javascript and HTML input | MEDIUM | 6.5 | Jun 27, 2019 |
| CVE-2019-10159 | cfme: Improper authorization in migration log controller allows any user to access VM migration logs | MEDIUM | 4.3 | Jun 14, 2019 |
| CVE-2017-15123 | CloudForms: RSS links are accessible without any authentication | MEDIUM | 5.3 | Jun 12, 2019 |
| CVE-2019-11358 | jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection | MEDIUM | 6.1 | Apr 19, 2019 |
| CVE-2019-5419 | rubygem-actionpack: denial of service vulnerability in Action View | HIGH | 7.5 | Mar 27, 2019 |
| CVE-2019-5418 KEV | rubygem-actionpack: render file directory traversal in Action View | HIGH | 7.5 | Mar 27, 2019 |
| CVE-2018-16476 | activejob: Information Exposure through deserialization using GlobalId | HIGH | 7.5 | Nov 30, 2018 |
| CVE-2016-5402 | cfme: RCE via Capacity & Utilization feature | HIGH | 8.8 | Oct 31, 2018 |
| CVE-2016-7047 | cfme: API leaks any MiqReportResult | MEDIUM | 4.3 | Sep 11, 2018 |
| CVE-2016-7071 | CFME: bypass authorization by altering VM ID | HIGH | 8.8 | Sep 10, 2018 |
| CVE-2017-2632 | cfme: tenant administrator can create a group with higher permissions | MEDIUM | 4.9 | Jul 27, 2018 |
| CVE-2017-2653 | CloudForms: UI security issue on Openstack actions | MEDIUM | 6.5 | Jul 27, 2018 |
| CVE-2017-12148 | Tower: modification of git hooks in SCM repo via upstream playbook execution | HIGH | 8.4 | Jul 27, 2018 |
Showing 1 to 25 of 50 CVEs