CVE-2013-6443
published 2014-01-23CVE-2013-6443: CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site…
PriorityP426medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
0.60%
44.8th percentile
CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | cloudforms | — | — |
| redhat | cloudforms_3.0_management_engine | <= 5.2.1 | — |
| redhat | cloudforms_3.0_management_engine | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vvp8-xf2f-vgc6: CloudForms 3
ghsa_unreviewed·2022-05-17
CVE-2013-6443 [MEDIUM] CWE-352 GHSA-vvp8-xf2f-vgc6: CloudForms 3
CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request.
Red Hat
CFME: GET request CSRF vulnerability
vendor_redhat·2014-01-14·CVSS 6.8
CVE-2013-6443 [MEDIUM] CWE-352 CFME: GET request CSRF vulnerability
CFME: GET request CSRF vulnerability
CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request.
No detection rules found.
No public exploits indexed.
2014-01-23
Published