Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 883227 - (CVE-2012-5622) CVE-2012-5622 openshift-console: CSRF attack
CVE-2012-5622 openshift-console: CSRF attack
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20121210,repo...
: Security
Depends On: 878754
Blocks: 883523
  Show dependency treegraph
 
Reported: 2012-12-03 23:58 EST by Kurt Seifried
Modified: 2016-03-04 07:46 EST (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2012-12-15 23:50:52 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2012:1555 normal SHIPPED_LIVE Important: openshift-console security update 2012-12-10 21:00:46 EST

  None (edit)
Description Kurt Seifried 2012-12-03 23:58:57 EST
Jeremy Choi of Red Hat reports:

There is no CSRF attack protection mechanism on the web console. While users 
are authenticated malicious links or scripts provided by attackers can cause 
unwanted action which the user does not want to do.
Comment 1 errata-xmlrpc 2012-12-10 16:03:52 EST
This issue has been addressed in following products:

  RHEL 6 Version of OpenShift Enterprise

Via RHSA-2012:1555 https://rhn.redhat.com/errata/RHSA-2012-1555.html
Comment 2 Murray McAllister 2012-12-18 19:56:07 EST
Acknowledgements:

This issue was discovered by Red Hat.

Note You need to log in before you can comment on or make changes to this bug.