Insecure Direct Object References (IDOR) and Access Control Bypass in Red Hat CloudForms 4.7 and 5

Insecure Direct Object References (IDOR) and Access Control Bypass in Red Hat CloudForms 4.7 and 5

CVE-2020-10779 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible to access some sensitive data within the CloudForms.

Learn more about our Cloud Audit.