Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not normally accessible.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14296
Reference (s):
- https://access.redhat.com/security/cve/cve-2020-14296
- https://bugzilla.redhat.com/show_bug.cgi?id=1847860
- URL: https://bugzilla.redhat.com/show_bug.cgi?id=1847860

