Vulnerabilities > CVE-2017-2632 - Incorrect Authorization vulnerability in Redhat Cloudforms and Cloudforms Management Engine

047910
CVSS 4.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
redhat
CWE-863

Summary

A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an attacker with tenant administration access to elevate privileges.

Common Weakness Enumeration (CWE)

Redhat

advisories
rhsa
idRHSA-2017:0320
rpms
  • cfme-0:5.7.1.3-1.el7cf
  • cfme-appliance-0:5.7.1.3-1.el7cf
  • cfme-appliance-debuginfo-0:5.7.1.3-1.el7cf
  • cfme-debuginfo-0:5.7.1.3-1.el7cf
  • cfme-gemset-0:5.7.1.3-1.el7cf