7.1
CVSSv3

CVE-2020-14296

Published: 11/08/2020 Updated: 12/08/2020
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 7.1 | Impact Score: 4.2 | Exploitability Score: 2.8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not normally accessible.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat cloudforms management engine 4.7

redhat cloudforms management engine 5.0

Vendor Advisories

Synopsis Critical: CloudForms 507 bug fix and enhancement update Type/Severity Security Advisory: Critical Topic An update is now available for CloudForms Management Engine 511Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (C ...