ZeroHour

CVE-2020-14296

CVSS 3.1
7.1 high
EPSS
<1%p49
Published
()
Modified
Description

Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not normally accessible.

Vendors
redhat
Products
cloudforms management engine
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.