CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within the rails application portion of CloudForms to escalate privileges.
| Software | From | Fixed in |
|---|---|---|
| redhat / cloudforms | 4.6 | 4.6.x |
| redhat / cloudforms_management_engine | 5.8 | 5.8.1 |
| redhat / cloudforms | 4.2 | 4.2.x |
| redhat / cloudforms_management_engine | - | 5.7.3 |