Bug 895345 (CVE-2013-0185)

Summary: CVE-2013-0185 ManageIQ EVM: CSRF
Product: [Other] Security Response Reporter: David Jorm <djorm>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: akarol, aneelica, dmetzger, gmccullo, gtanzill, jfrey, jhardy, mjc, obarenbo, roliveri, security-response-team, simaishi, smallamp
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-11-13 01:09:26 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 957579    
Bug Blocks: 895349, 895358, 1011266    

Description David Jorm 2013-01-15 05:19:51 UTC
ManageIQ EVM is vulnerable to Cross-Site Request Forgery (CSRF) attacks. A remote attacker could provide a specially-crafted web page that, when visited by a user logged in to ManageIQ EVM, could allow the attacker to trigger actions on the ManageIQ EVM server in the context of the user.

Comment 1 Arun Babu Neelicattu 2013-01-29 03:09:13 UTC
Acknowledgements:

This issue was discovered by David Jorm of the Red Hat Security Response Team.

Comment 4 David Jorm 2013-11-13 01:09:26 UTC
Statement:

This issue is resolved in CloudForms 3.0. The maintenance support policy for CloudForms 2.0 only covers critical security issues, meaning this issue is out of scope. Users of CloudForms 2.0 are advised to upgrade to CloudForms 3.0 to address this issue.