CVE-2020-14296: Red Hat Cloudforms Management Engine
High severity, CVSS 7.1. EPSS: 0.6% chance of exploitation in the next 30 days.
Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not normally accessible.
Affected products
- Red Hat Cloudforms Management Engine: version 4.7 only; version 5.0 only
Published 2020-08-11. Last modified 2026-06-17.