CVE-2017-15123
Summary
| CVE | CVE-2017-15123 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-12 14:29:00 UTC |
| Updated | 2019-07-17 14:15:00 UTC |
| Description | A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created virtual machines. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Cloudforms Management Engine | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1524720 – (CVE-2017-15123) CVE-2017-15123 CloudForms: RSS links are accessible without any authentication | CONFIRM | bugzilla.redhat.com | Issue Tracking, Vendor Advisory |
| Red Hat CloudForms CVE-2017-15123 Information Disclosure Vulnerability | BID | www.securityfocus.com | |
| CVE-2017-15123 Exploit – HacKeD | MISC | hacked0x90.wordpress.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.