CVE-2014-0026: CSRF
Published Dec 11, 2019
·Updated
katello-headpin is vulnerable to CSRF in REST API
Affected Software
1 affected component
redhat Subscription Asset Manager=1.0.0
Event History
Dec 11, 2019
CVE Published
via MITRE·02:07 PM
Data Sourced
via MITRE·02:07 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2014-0026?
CVE-2014-0026 is a vulnerability in katello-headpin that allows CSRF attacks through the REST API.
2
How severe is CVE-2014-0026?
CVE-2014-0026 has a severity rating of medium.
3
Which software versions are affected by CVE-2014-0026?
CVE-2014-0026 affects Redhat Subscription Asset Manager version 1.0.0.
4
How can I fix CVE-2014-0026?
To fix CVE-2014-0026, update katello-headpin to a patched version provided by Redhat.
5
Where can I find more information about CVE-2014-0026?
You can find more information about CVE-2014-0026 on the Redhat Security Advisory page and the Bugzilla page.