Red Hat Bugzilla – Bug 1059432
CVE-2014-0026 katello-headpin: CSRF in REST API
Last modified: 2014-11-10 05:07:34 EST
Hui Wang and Keqin Hong of Red Hat report: All REST APIs in SAM are vulnerable to CSRF ( Cross-site request forgery ) which forces an end user to execute unwanted actions on a web application in which he/she is currently authenticated.
Acknowledgements: This issue was discovered by Hui Wang and Lingyan Zhuang of Red Hat.
Statement: This issue affects the versions of katello-headpin as shipped with Red Hat Subscription Asset Manager 1. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.