Vulnerability record · CVE-2020-14325 · published 11 August 2020
CVE-2020-14325: Redhat cloudforms vulnerability
Redhat · Cloudforms
Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and non-existent role-based access control user, with groups and roles. With a selected group of EvmGroup-super_administrator, an attacker can perform any API request as a super administrator.
Description
Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and non-existent role-based access control user, with groups and roles. With a selected group of EvmGroup-super_administrator, an attacker can perform any API request as a super administrator.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/security/cve/cve-2020-14325 | MitigationVendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1855739 | Issue TrackingMitigationVendor Advisory |
| https://access.redhat.com/security/cve/cve-2020-14325 | MitigationVendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1855739 | Issue TrackingMitigationVendor Advisory |
Track CVE-2020-14325 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-14325), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.