A flaw was found in the CloudForms API before 5.6.3.0, 5...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Sep 11, 2018
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 1, 2023
A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.
References