Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0185

Опубликовано: 13 нояб. 2013
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.

Отчет

This issue is resolved in CloudForms 3.0. The maintenance support policy for CloudForms 2.0 only covers critical security issues, meaning this issue is out of scope. Users of CloudForms 2.0 are advised to upgrade to CloudForms 3.0 to address this issue.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-352

EPSS

Процентиль: 41%
0.0019
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.8
nvd
почти 8 лет назад

Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.

CVSS3: 8.8
github
почти 4 года назад

Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.

EPSS

Процентиль: 41%
0.0019
Низкий

4.3 Medium

CVSS2