Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-6443

Опубликовано: 23 янв. 2014
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:cloudforms:3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_3.0_management_engine:*:*:*:*:*:*:*:*
Версия до 5.2.1 (включая)
cpe:2.3:a:redhat:cloudforms_3.0_management_engine:5.2:*:*:*:*:*:*:*

EPSS

Процентиль: 27%
0.00095
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-352

Связанные уязвимости

redhat
около 12 лет назад

CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request.

github
больше 3 лет назад

CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request.

EPSS

Процентиль: 27%
0.00095
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-352