First published: Thu Jan 23 2014(Updated: )
CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat CloudForms | =3.0 | |
Red Hat CloudForms Management Engine | <=5.2.1 | |
Red Hat CloudForms Management Engine | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6443 has a high severity rating due to its potential to allow cross-site request forgery attacks.
To fix CVE-2013-6443, upgrade CloudForms Management Engine to version 5.2.1.6 or later.
CVE-2013-6443 affects Red Hat CloudForms 3.0 and versions of the CloudForms Management Engine prior to 5.2.1.6.
CVE-2013-6443 allows remote attackers to conduct cross-site request forgery attacks.
Yes, CVE-2013-6443 is a recognized vulnerability detailed in security advisories.