Bug 1311649

Summary: graphite-web: CSRF vulnerabilities in webapp/graphite/account/views.py
Product: [Other] Security Response Reporter: Adam Mariš <amaris>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abaron, aortega, apevec, ayoung, carnil, ceph-eng-bugs, chrisw, dallan, gkotton, jonathansteffan, jschluet, lhh, lpeer, markmc, piotr1212, rbryant, sclewis, sisharma, srevivo, tdecacqu
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-05-18 06:59:36 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 1311650, 1311651    
Bug Blocks: 1311652    

Description Adam Mariš 2016-02-24 16:43:50 UTC
CSRF vulnerabilities in functions in webapp/graphite/account/views.py were reported.

Upstream bug:

https://github.com/graphite-project/graphite-web/issues/1441

CVE request:

http://seclists.org/oss-sec/2016/q1/376

Comment 1 Adam Mariš 2016-02-24 16:44:28 UTC
Created graphite-web tracking bugs for this issue:

Affects: fedora-all [bug 1311650]
Affects: epel-all [bug 1311651]