CVE-2020-10778

In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavior.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:cloudforms:4.7:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms:5.0.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-08-11 13:15

Updated : 2023-12-10 13:27


NVD link : CVE-2020-10778

Mitre link : CVE-2020-10778

CVE.ORG link : CVE-2020-10778


JSON object : View

Products Affected

redhat

  • cloudforms
CWE
CWE-669

Incorrect Resource Transfer Between Spheres