A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an attacker with tenant administration access to elevate privileges.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2018-07-27T19:00:00
Updated: 2024-08-05T14:02:06.842Z
Reserved: 2016-12-01T00:00:00
Link: CVE-2017-2632
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-07-27T19:29:00.487
Modified: 2019-10-09T23:26:59.383
Link: CVE-2017-2632
Redhat