CVE-2014-1211: CSRF
Published Jan 17, 2014
·Updated
Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.
Affected Software
3 affected components
VMware vCloud Director=5.1.0
VMware vCloud Director=5.1.1
VMware vCloud Director=5.1.2
Event History
Jan 17, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·09:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1211?
The severity of CVE-2014-1211 is considered medium due to the impact it can have on user authentication.
2
How do I fix CVE-2014-1211?
To fix CVE-2014-1211, upgrade VMware vCloud Director to version 5.1.3 or later.
3
What versions of VMware vCloud Director are affected by CVE-2014-1211?
CVE-2014-1211 affects VMware vCloud Director versions 5.1.0, 5.1.1, and 5.1.2.
4
What is the impact of CVE-2014-1211?
The impact of CVE-2014-1211 allows remote attackers to hijack user sessions and trigger unwanted logouts.
5
Is there a workaround for CVE-2014-1211?
A recommended workaround for CVE-2014-1211 is to disable CSRF protection within the application until an upgrade can be performed.