CVE-2017-15123 Information
Feb 14, 2021
cve
Description
A flaw was found in the CloudForms web interface versions 5.8 - 5.10 where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created virtual machines.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
http://www.securityfocus.com/bid/108690 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15123 https://hacked0x90.wordpress.com/2019/07/17/cve-2017-15123-exploit/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: