CVE-2013-0196
published 2019-12-30CVE-2013-0196: A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.43%
35.6th percentile
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openshift | openshift_enterprise | — | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2w57-4v2r-38c4: A CSRF issue was found in OpenShift Enterprise 1
ghsa_unreviewed·2022-05-05
CVE-2013-0196 [MEDIUM] CWE-352 GHSA-2w57-4v2r-38c4: A CSRF issue was found in OpenShift Enterprise 1
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser.
Red Hat
OpenShift Enterprise and Online vulnerable to CSRF attack with REST API
vendor_redhat·2014-09-05·CVSS 6.5
CVE-2013-0196 [MEDIUM] CWE-352 OpenShift Enterprise and Online vulnerable to CSRF attack with REST API
OpenShift Enterprise and Online vulnerable to CSRF attack with REST API
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser.
Red Hat
kernel: pty layer race condition leading to memory corruption
vendor_redhat·2014-05-01·CVSS 5.5
CVE-2014-0196 [MEDIUM] kernel: pty layer race condition leading to memory corruption
kernel: pty layer race condition leading to memory corruption
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
Statement: This issue did not affect the versions of the Linux kernel packages as shipped with Red Hat Enterprise Linux 5.
This issue affected the versions of the Linux kernel packages as shipped with Red Hat Enterprise Linux 6 prior to version kernel-2.6.32-358.6.1.el6, released via RHSA-2013:0744 (https://rhn.redhat.com/errata/RHSA-2013-0744.html). That update added a backport of
No detection rules found.
No public exploits indexed.
2019-12-30
Published