CVE-2020-14369
02.12.2020, 15:15
This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a web application in which the user is currently authenticated. An attacker can make a forgery HTTP request to the server by crafting custom flash file which can force the user to perform state changing requests like provisioning VMs, running ansible playbooks and so forth.
| Vendor | Product | Version |
|---|---|---|
| redhat | cloudforms | 𝑥 ≤ 5.11 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration