Red Hat Bugzilla – Bug 901364
CVE-2013-0196 OpenShift Enterprise and Online vulnerable to CSRF attack with REST API
Last modified: 2016-03-04 06:36:55 EST
Jeremy Choi (jechoi@redhat.com) of Red Hat reports: Description of problem: Since the web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism, the credential, the Authorization: header, can be sent when requesting the REST API via web browser. As a result, while users are authenticated malicious links or scripts provided by attackers can cause unwanted action.
Acknowledgements: This issue was discovered by Jeremy Choi of the Red Hat Hosted and Shared Services team.
This issue was addressed in http://rhn.redhat.com/errata/RHEA-2013-1031.html