Bug 895345 (CVE-2013-0185) - CVE-2013-0185 ManageIQ EVM: CSRF
Summary: CVE-2013-0185 ManageIQ EVM: CSRF
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: CVE-2013-0185
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 957579
Blocks: 895349 895358 1011266
TreeView+ depends on / blocked
 
Reported: 2013-01-15 05:19 UTC by David Jorm
Modified: 2021-02-17 08:11 UTC (History)
13 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-11-13 01:09:26 UTC


Attachments (Terms of Use)

Description David Jorm 2013-01-15 05:19:51 UTC
ManageIQ EVM is vulnerable to Cross-Site Request Forgery (CSRF) attacks. A remote attacker could provide a specially-crafted web page that, when visited by a user logged in to ManageIQ EVM, could allow the attacker to trigger actions on the ManageIQ EVM server in the context of the user.

Comment 1 Arun Babu Neelicattu 2013-01-29 03:09:13 UTC
Acknowledgements:

This issue was discovered by David Jorm of the Red Hat Security Response Team.

Comment 4 David Jorm 2013-11-13 01:09:26 UTC
Statement:

This issue is resolved in CloudForms 3.0. The maintenance support policy for CloudForms 2.0 only covers critical security issues, meaning this issue is out of scope. Users of CloudForms 2.0 are advised to upgrade to CloudForms 3.0 to address this issue.


Note You need to log in before you can comment on or make changes to this bug.