Bug 1750928 (CVE-2019-14836)

Summary: CVE-2019-14836 3scale: dev portal missing protection against login CSRF
Product: [Other] Security Response Reporter: Chess Hazlett <chazlett>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: amackenz, amasferr, chazlett, drieden, hramihaj, mkudlej, sbunciak, security-response-team, tjochec
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
It was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks.
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-27 10:48:44 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1750562, 1942917    

Description Chess Hazlett 2019-09-10 19:04:43 UTC
3scale dev portal login form does not verify CSRF token, and so does not protect against login CSRF.

Comment 3 hramihaj 2021-05-25 16:36:25 UTC
We tried to verify that with a crafted Cross Site page (as in CSRF). We can't reproduce the issue. Can you provide a full procedure on to reproduce the issue?

Thank you.

The result is:

Access Denied
Sorry, you do not have permission to access this page.