Vulnerabilities > CVE-2018-10854 - Unspecified vulnerability in Redhat Cloudforms Management Engine 4.7/5.8/5.9

047910
CVSS 5.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
redhat

Summary

cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure mapping delete feature. A stored cross-site scripting due to improper sanitization of user input in Name field.

Redhat

rpms
  • ansible-tower-0:3.5.2-1.el7at
  • ansible-tower-server-0:3.5.2-1.el7at
  • ansible-tower-setup-0:3.5.2-1.el7at
  • ansible-tower-ui-0:3.5.2-1.el7at
  • ansible-tower-venv-ansible-0:3.5.2-1.el7at
  • ansible-tower-venv-tower-0:3.5.2-1.el7at
  • cfme-0:5.10.9.1-1.el7cf
  • cfme-amazon-smartstate-0:5.10.9.1-1.el7cf
  • cfme-appliance-0:5.10.9.1-1.el7cf
  • cfme-appliance-common-0:5.10.9.1-1.el7cf
  • cfme-appliance-debuginfo-0:5.10.9.1-1.el7cf
  • cfme-appliance-tools-0:5.10.9.1-1.el7cf
  • cfme-debuginfo-0:5.10.9.1-1.el7cf
  • cfme-gemset-0:5.10.9.1-1.el7cf
  • cfme-gemset-debuginfo-0:5.10.9.1-1.el7cf
  • ovirt-ansible-hosted-engine-setup-0:1.0.23-1.el7ev
  • ovirt-ansible-roles-0:1.1.7-1.el7ev
  • ovirt-ansible-vm-infra-0:1.1.19-1.el7ev
  • v2v-conversion-host-ansible-0:1.14.2-1.el7ev
  • v2v-conversion-host-wrapper-0:1.14.2-1.el7ev