漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing when invoking arbitrary methods via filtering on VMs that MiqExpression will execute that is triggerable by API users. An attacker could use this to execute actions they should not be allowed to (e.g. destroying VMs).
CVSS Information
N/A
Vulnerability Type
授权机制缺失
Vulnerability Title
Red Hat CloudForms Management Engine 权限许可和访问控制漏洞
Vulnerability Description
Red Hat CloudForms Management Engine(CFME)是美国红帽(Red Hat)公司的一个IaaS(基础设施即服务)云服务解决方案的管理引擎。 Red Hat CFME 5.7.3之前版本和5.8.1之前的5.8.x版本中存在提权漏洞,该漏洞源于在调用任意方法时,程序没有检查其权限。远程攻击者可利用该漏洞执行无权执行的操作(破坏VMs)。
CVSS Information
N/A
Vulnerability Type
N/A