Vulnerability index

Browse CVEs

34 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Quay MEDIUM 6.5
CVE-2023-4959

A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, i…

Mitigation only
Fix from $1,600 2023-09-15
Data Grid HIGH 7.1
CVE-2020-10771

A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw…

Mitigation only
Fix from $1,950 2021-06-02
3scale HIGH 8.8
CVE-2019-14836

A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to…

Mitigation only
Fix from $1,950 2021-05-26
Cloudforms MEDIUM 6.3
CVE-2020-14369

This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a…

Fix: after 5.11
Fix from $1,600 2020-12-02
Amq Online MEDIUM 5.9
CVE-2020-14319

It was found that the AMQ Online console is vulnerable to a Cross-Site Request Forgery (CSRF) which is exploitable in cases where preflight checks ar…

Fix: 0.32.2 / 1.5.2+
Fix from $1,600 2020-08-03
Quay HIGH 8.8
CVE-2019-3864

A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which i…

Fix: 3.0.0+
Fix from $1,950 2020-01-21
Satellite MEDIUM 6.5
CVE-2014-3590

Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log …

Mitigation only
Fix from $1,600 2020-01-02
Openshift MEDIUM 6.5
CVE-2013-0196

A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection me…

No fix yet
Fix from $1,600 2019-12-30
Cloudforms HIGH 8.8
CVE-2014-0197

CFME: CSRF protection vulnerability via permissive check of the referrer header

Fix: after 5.9.3.1
Fix from $1,950 2019-12-13
Subscription Asset Manager MEDIUM 6.5
CVE-2014-0026

katello-headpin is vulnerable to CSRF in REST API

No fix yet
Fix from $1,600 2019-12-11
Jboss Application Server MEDIUM 6.5
CVE-2011-3609

A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for …

Mitigation only
Fix from $1,600 2019-11-26
Keycloak HIGH 8.8
CVE-2019-10199

It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw t…

Fix: after 6.0.1
Fix from $1,950 2019-08-14
Openshift Container Platform MEDIUM 5.4
CVE-2019-10176

A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found …

Mitigation only
Fix from $1,600 2019-08-02
Openstack HIGH 8.8
CVE-2018-10899

A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly c…

Fix: 1.6.1+
Fix from $1,950 2019-08-01
Openshift Container Platform MEDIUM 6.3
CVE-2019-3876

A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X…

Fix: after 3.11
Fix from $1,600 2019-04-01
Enterprise Linux Desktop HIGH 8.8
CVE-2018-12364

NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect t…

Mitigation only
Fix from $1,950 2018-10-18
Ansible Tower HIGH 8.8
CVE-2018-10884

Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could expl…

Fix: after 3.2.6
Fix from $1,950 2018-08-22
Manageiq Enterprise Virtualization Manager HIGH 8.8
CVE-2013-0185

Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authenticat…

No fix yet
Fix from $1,950 2018-05-01
Etcd HIGH 8.8
CVE-2018-1098

A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd…

Fix: after 3.3.1
Fix from $1,950 2018-04-03
Jboss Fuse HIGH 8.8
CVE-2014-0120

Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary us…

Fix: after 1.2.2
Fix from $1,950 2017-12-29
Amq HIGH 8.8
CVE-2015-5182

Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.

Mitigation only
Fix from $1,950 2017-09-25
Jboss Bpm Suite HIGH 8.8
CVE-2016-5401

Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for re…

Mitigation only
Fix from $1,950 2017-04-20
Jboss Bpm Suite HIGH 8.8
CVE-2016-7034

The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query s…

Mitigation only
Fix from $1,950 2016-09-07
Openshift HIGH 8.8
CVE-2015-7537

Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication o…

Fix: after 3.1
Fix from $1,950 2016-02-03
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2015-5188

Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly …

Fix: after 6.4.3
Fix from $1,600 2015-10-27
Ovirt Engine MEDIUM 6.8
CVE-2014-0151

Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for …

Fix: after 3.5.0
Fix from $1,600 2015-02-13
Cloudforms MEDIUM 6.8
CVE-2013-6443

CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-…

Fix: after 5.2.1
Fix from $1,600 2014-01-23
Enterprise Mrg MEDIUM 6.8
CVE-2013-4405

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allow remote attackers t…

Mitigation only
Fix from $1,600 2013-12-23
Jboss Enterprise Portal Platform MEDIUM 6.8
CVE-2012-3532

Cross-site request forgery (CSRF) vulnerability in the GateIn Portal component in JBoss Enterprise Portal Platform 5.2.2 and earlier allows remote at…

Fix: after 5.2.2
Fix from $1,600 2013-04-12
Openshift MEDIUM 6.8
CVE-2012-5622

Cross-site request forgery (CSRF) vulnerability in the management console (openshift-console/app/controllers/application_controller.rb) in OpenShift …

Patch available
Fix from $1,600 2012-12-18