Vulnerability index

Browse CVEs

34 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.5 CVE-2023-4959 A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, i… Quay Mitigation only Fix from $1,6002023-09-15 HIGH 7.1 CVE-2020-10771 A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw… Data Grid Mitigation only Fix from $1,9502021-06-02 HIGH 8.8 CVE-2019-14836 A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to… 3scale Mitigation only Fix from $1,9502021-05-26 MEDIUM 6.3 CVE-2020-14369 This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a… Cloudforms after 5.11 Fix from $1,6002020-12-02 MEDIUM 5.9 CVE-2020-14319 It was found that the AMQ Online console is vulnerable to a Cross-Site Request Forgery (CSRF) which is exploitable in cases where preflight checks ar… Amq Online 0.32.2 / 1.5.2+ Fix from $1,6002020-08-03 HIGH 8.8 CVE-2019-3864 A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which i… Quay 3.0.0+ Fix from $1,9502020-01-21 MEDIUM 6.5 CVE-2014-3590 Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log … Satellite Mitigation only Fix from $1,6002020-01-02 MEDIUM 6.5 CVE-2013-0196 A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection me… Openshift No fix yet Fix from $1,6002019-12-30 HIGH 8.8 CVE-2014-0197 CFME: CSRF protection vulnerability via permissive check of the referrer header Cloudforms after 5.9.3.1 Fix from $1,9502019-12-13 MEDIUM 6.5 CVE-2014-0026 katello-headpin is vulnerable to CSRF in REST API Subscription Asset Manager No fix yet Fix from $1,6002019-12-11 MEDIUM 6.5 CVE-2011-3609 A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for … Jboss Application Server Mitigation only Fix from $1,6002019-11-26 HIGH 8.8 CVE-2019-10199 It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw t… Keycloak after 6.0.1 Fix from $1,9502019-08-14 MEDIUM 5.4 CVE-2019-10176 A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found … Openshift Container Platform Mitigation only Fix from $1,6002019-08-02 HIGH 8.8 CVE-2018-10899 A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly c… Openstack 1.6.1+ Fix from $1,9502019-08-01 MEDIUM 6.3 CVE-2019-3876 A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X… Openshift Container Platform after 3.11 Fix from $1,6002019-04-01 HIGH 8.8 CVE-2018-12364 NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect t… Enterprise Linux Desktop Mitigation only Fix from $1,9502018-10-18 HIGH 8.8 CVE-2018-10884 Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could expl… Ansible Tower after 3.2.6 Fix from $1,9502018-08-22 HIGH 8.8 CVE-2013-0185 Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authenticat… Manageiq Enterprise Virtualization Manager No fix yet Fix from $1,9502018-05-01 HIGH 8.8 CVE-2018-1098 A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd… Etcd after 3.3.1 Fix from $1,9502018-04-03 HIGH 8.8 CVE-2014-0120 Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary us… Jboss Fuse after 1.2.2 Fix from $1,9502017-12-29 HIGH 8.8 CVE-2015-5182 Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ. Amq Mitigation only Fix from $1,9502017-09-25 HIGH 8.8 CVE-2016-5401 Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for re… Jboss Bpm Suite Mitigation only Fix from $1,9502017-04-20 HIGH 8.8 CVE-2016-7034 The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query s… Jboss Bpm Suite Mitigation only Fix from $1,9502016-09-07 HIGH 8.8 CVE-2015-7537 Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication o… Openshift after 3.1 Fix from $1,9502016-02-03 MEDIUM 6.8 CVE-2015-5188 Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly … Jboss Enterprise Application Platform after 6.4.3 Fix from $1,6002015-10-27 MEDIUM 6.8 CVE-2014-0151 Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for … Ovirt Engine after 3.5.0 Fix from $1,6002015-02-13 MEDIUM 6.8 CVE-2013-6443 CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-… Cloudforms after 5.2.1 Fix from $1,6002014-01-23 MEDIUM 6.8 CVE-2013-4405 Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allow remote attackers t… Enterprise Mrg Mitigation only Fix from $1,6002013-12-23 MEDIUM 6.8 CVE-2012-3532 Cross-site request forgery (CSRF) vulnerability in the GateIn Portal component in JBoss Enterprise Portal Platform 5.2.2 and earlier allows remote at… Jboss Enterprise Portal Platform after 5.2.2 Fix from $1,6002013-04-12 MEDIUM 6.8 CVE-2012-5622 Cross-site request forgery (CSRF) vulnerability in the management console (openshift-console/app/controllers/application_controller.rb) in OpenShift … Openshift Patch available Fix from $1,6002012-12-18