Total vulnerabilities in the database
A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.
Software | From | Fixed in |
---|---|---|
redhat / cloudforms | 4.5 | 4.5.x |
redhat / cloudforms | 4.2 | 4.2.x |
redhat / cloudforms_management_engine | 5.8 | 5.8.1.2 |
redhat / cloudforms_management_engine | 5.6 | 5.6.3.0 |
redhat / cloudforms_management_engine | 5.7 | 5.7.3.1 |