CVE-2017-2653

Severity
6.5MEDIUM
EPSS
0.2%
top 56.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27
Latest updateMay 13

Description

A number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead of just POST requests. This could allow an attacker to bypass the protect_from_forgery XSRF protection causing the routes to be used. This attack would require additional cross-site scripting or similar attacks in order to execute.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:NExploitability: 2.3 | Impact: 1.4

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-xfgx-c33h-jf9f: A number of unused delete routes are present in CloudForms before 52022-05-13
CVEList
CVE-2017-2653: A number of unused delete routes are present in CloudForms before 52018-07-27

📋Vendor Advisories

1
Red Hat
CloudForms: UI security issue on Openstack actions2017-03-14

💬Community

2
Bugzilla
CVE-2017-7595 libtiff: Divide-by-zero in JPEGSetupEncode (tiff_jpeg.c)2017-04-11
Bugzilla
CVE-2017-2653 CloudForms: UI security issue on Openstack actions2017-03-14
CVE-2017-2653 (MEDIUM CVSS 6.5) | A number of unused delete routes ar | cvebase.io