CVE-2020-10778: Red Hat Cloudforms
Medium severity, CVSS 6.0. EPSS: 0.9% chance of exploitation in the next 30 days.
In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavior.
Affected products
- Red Hat Cloudforms: version 4.7 only; version 5.0.0 only
Published 2020-08-11. Last modified 2026-06-17.