First published: Mon Mar 26 2018(Updated: )
Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 and 8.1.0.2 is affected by a cross-site request forgery vulnerability. A malicious user may potentially exploit this vulnerability to send unauthorized requests to the server on behalf of authenticated users of the application.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Isilon OneFS | >=7.2.1.0<=7.2.1.6 | |
Dell EMC Isilon OneFS | >=8.0.0.0<=8.0.0.6 | |
Dell EMC Isilon OneFS | >=8.0.1.0<=8.0.1.2 | |
Dell EMC Isilon OneFS | >=8.1.0.0<=8.1.0.1 | |
Dell EMC Isilon OneFS | =7.1.1.11 | |
Dell EMC Isilon OneFS | =8.1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1213 is a cross-site request forgery vulnerability affecting Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 and 8.1.0.2.
The severity of CVE-2018-1213 is 8.8 (High).
CVE-2018-1213 affects Dell EMC Isilon OneFS by allowing a malicious user to send unauthorized requests via cross-site request forgery.
CVE-2018-1213 can be exploited by a malicious user who can potentially send unauthorized requests through the cross-site request forgery vulnerability.
Yes, you can find references for CVE-2018-1213 at the following links: [1](http://seclists.org/fulldisclosure/2018/Mar/50), [2](http://www.securityfocus.com/bid/103033), [3](https://www.coresecurity.com/advisories/dell-emc-isilon-onefs-multiple-vulnerabilities).