← Back to CVE List

CVE-2017-7530

Published: 2018-07-26T13:29Z
Last Modified: 2024-11-21T03:32Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing when invoking arbitrary methods via filtering on VMs that MiqExpression will execute that is triggerable by API users. An attacker could use this to execute actions they should not be allowed to (e.g. destroying VMs). > MITRE Terms of Use apply – see LICENSE‑MITRE.txt