A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an attacker with tenant administration access to elevate privileges.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2632 | issue tracking third party advisory |
http://www.securityfocus.com/bid/96478 | vdb entry third party advisory |
http://rhn.redhat.com/errata/RHSA-2017-0320.html | third party advisory vendor advisory |