Total vulnerabilities in the database
Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not normally accessible.
Software | From | Fixed in |
---|---|---|
redhat / cloudforms_management_engine | 5.0 | 5.0.x |
redhat / cloudforms_management_engine | 4.7 | 4.7.x |