Loading
Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and non-existent role-based access control user, with groups and roles. With a selected group of EvmGroup-super_administrator, an attacker can perform any API request as a super administrator.
Use Redhat vendor hub and Cloudforms product page to widen CVE-2020-14325 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2014-0197, CVE-2020-10783 and CVE-2020-25716 for nearby disclosures in the same product family.