CVE-2013-6443
medium
CVSS v3
—
CVSS v2
6.8
VIR risk
6.8
Description
CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2014-0025.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| redhat | cloudforms | 3.0 | |
| redhat | cloudforms_3.0_management_engine | {"endIncluding":"5.2.1"} | |
| redhat | cloudforms_3.0_management_engine | 5.2 | |
References
CWEs
CWE-352
Verify integrity in audit chain (admin only). AS-IS.