CVE-2013-6443: CSRF
Published Jan 23, 2014
·Updated
CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protectfromforgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request.
Affected Software
3 affected components
redhat Cloudforms=3.0
redhat Cloudforms 3.0 Management Engine<=5.2.1
redhat Cloudforms 3.0 Management Engine=5.2
Event History
Jan 23, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6443?
CVE-2013-6443 has a high severity rating due to its potential to allow cross-site request forgery attacks.
2
How do I fix CVE-2013-6443?
To fix CVE-2013-6443, upgrade CloudForms Management Engine to version 5.2.1.6 or later.
3
What systems are affected by CVE-2013-6443?
CVE-2013-6443 affects Red Hat CloudForms 3.0 and versions of the CloudForms Management Engine prior to 5.2.1.6.
4
What types of attacks does CVE-2013-6443 allow?
CVE-2013-6443 allows remote attackers to conduct cross-site request forgery attacks.
5
Is CVE-2013-6443 a known vulnerability?
Yes, CVE-2013-6443 is a recognized vulnerability detailed in security advisories.