CVE-2017-7497
Summary
| CVE | CVE-2017-7497 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-27 15:29:00 UTC |
| Updated | 2023-02-12 23:30:00 UTC |
| Description | The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant. |
Risk And Classification
Problem Types: CWE-284
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Cloudforms Management Engine | 5.7.2 | All | All | All |
| Application | Redhat | Cloudforms Management Engine | 5.8.0 | All | All | All |
| Application | Redhat | Cloudforms Management Engine | 5.7.2 | All | All | All |
| Application | Redhat | Cloudforms Management Engine | 5.8.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2017-7497 - Red Hat Customer Portal | MISC | access.redhat.com | |
| Bug 1450150 – CFME: Dialog for creating cloud volumes does not filter cloud tenants CVE-2017-7497 | MISC | bugzilla.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Vendor Advisory |
| 1450150 – (CVE-2017-7497) CFME: Dialog for creating cloud volumes does not filter cloud tenants CVE-2017-7497 | CONFIRM | bugzilla.redhat.com | Issue Tracking, Patch, Vendor Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.