The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.
References
Link | Resource |
---|---|
https://access.redhat.com/errata/RHSA-2017:1601 | Vendor Advisory |
https://access.redhat.com/errata/RHSA-2017:1758 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7497 | Issue Tracking Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2018-07-27 15:29
Updated : 2023-02-12 23:30
NVD link : CVE-2017-7497
Mitre link : CVE-2017-7497
CVE.ORG link : CVE-2017-7497
JSON object : View
Products Affected
redhat
- cloudforms_management_engine
CWE