CVE-2020-14369

MEDIUM

Red Hat CloudForms < 5.11 - Cross-Site Request Forgery via Crafted Flash File

Title source: llm
STIX 2.1

Description

This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a web application in which the user is currently authenticated. An attacker can make a forgery HTTP request to the server by crafting custom flash file which can force the user to perform state changing requests like provisioning VMs, running ansible playbooks and so forth.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1871921

Scores

CVSS v3 6.3
EPSS 0.0011
EPSS Percentile 29.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Details

CWE
CWE-352
Status published
Products (1)
redhat/cloudforms < 5.11
Published Dec 02, 2020
Tracked Since Feb 18, 2026