CVE-2013-0185: CSRF
Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
Other sources
ManageIQ EVM is vulnerable to Cross-Site Request Forgery (CSRF) attacks. A remote attacker could provide a specially-crafted web page that, when visited by a user logged in to ManageIQ EVM, could allow the attacker to trigger actions on the ManageIQ EVM server in the context of the user.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2013-0185.
What is the severity of CVE-2013-0185?
The severity of CVE-2013-0185 is high.
What is the affected software?
The affected software is Redhat ManageIQ Enterprise Virtualization Manager.
How does the vulnerability work?
The vulnerability allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
Is there a fix available for CVE-2013-0185?
Please refer to the reference link for information on how to fix CVE-2013-0185.