Skip to content

Business logic bypass through widgets

High
Fryguy published GHSA-2r6j-p8gp-5649 Aug 17, 2020

Package

No package listed

Affected versions

>= ivanchuk

Patched versions

ivanchuk-7, jansa-1-rc2

Description

Description

A business logic flaw was found in ManageIQ where the read-only values of the Widgets could be altered. An attacker with low privileges could bypass server-side validation by dropping the disabled attribute from the fields.

Acknowledgements

Red Hat would like to thank Purnachand Pulahari (IBM) and Ranjit Kumar Singh (IBM) for reporting this issue.

https://access.redhat.com/security/cve/cve-2020-10778


Fixed in ivanchuk-7, jansa-1-rc2, master

Severity

High

CVE ID

CVE-2020-10778

Weaknesses

No CWEs