Bug 1072681 (CVE-2014-0120)
Summary: | CVE-2014-0120 hawtio-karaf-terminal: cross-site request forgery (CSRF) | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Trevor Jay <tjay> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | chazlett, djorm, jrusnack, security-response-team, weli |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2014-04-14 18:42:04 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 1072724 |
Description
Trevor Jay
2014-03-05 02:52:18 UTC
Acknowledgements: This issue was discovered by David Jorm of the Red Hat Security Response Team. Upstream patch commit: https://github.com/hawtio/hawtio/commit/b4e23e002639c274a2f687ada980118512f06113 Statement: Not vulnerable. This issue only affects Red Hat JBoss Fuse 6.1.0 Beta. It is resolved in the general availability release of Red Hat JBoss Fuse 6.1.0. Earlier versions of Red Hat JBoss Fuse are not affected, as they did not include the hawtio-karaf-terminal component. |