In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavior.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-3191 In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavior.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-04T11:14:15.585Z

Reserved: 2020-03-20T00:00:00

Link: CVE-2020-10778

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-08-11T13:15:12.040

Modified: 2024-11-21T04:56:03.193

Link: CVE-2020-10778

cve-icon Redhat

Severity : Important

Publid Date: 2020-08-03T13:30:00Z

Links: CVE-2020-10778 - Bugzilla

cve-icon OpenCVE Enrichment

No data.