CVE-2017-15123 Information

Description

A flaw was found in the CloudForms web interface versions 5.8 - 5.10 where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created virtual machines.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Reference

http://www.securityfocus.com/bid/108690 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15123 https://hacked0x90.wordpress.com/2019/07/17/cve-2017-15123-exploit/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

NONE

Base Score

NONE

Base Severity

5.3

Share on: