Total vulnerabilities in the database
cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure mapping delete feature. A stored cross-site scripting due to improper sanitization of user input in Name field.
Software | From | Fixed in |
---|---|---|
redhat / cloudforms_management_engine | 4.7 | 4.7.x |
redhat / cloudforms_management_engine | 5.8 | 5.8.x |
redhat / cloudforms_management_engine | 5.9 | 5.9.x |