ManageIQ EVM is vulnerable to Cross-Site Request Forgery (CSRF) attacks. A remote attacker could provide a specially-crafted web page that, when visited by a user logged in to ManageIQ EVM, could allow the attacker to trigger actions on the ManageIQ EVM server in the context of the user.
Acknowledgements: This issue was discovered by David Jorm of the Red Hat Security Response Team.
Statement: This issue is resolved in CloudForms 3.0. The maintenance support policy for CloudForms 2.0 only covers critical security issues, meaning this issue is out of scope. Users of CloudForms 2.0 are advised to upgrade to CloudForms 3.0 to address this issue.