CVE-2013-4405

medium

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allow remote attackers to hijack the authentication of cumin users for unspecified requests.

References

http://rhn.redhat.com/errata/RHSA-2013-1851.html

http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=998561

http://rhn.redhat.com/errata/RHSA-2013-1852.html

Details

Source: MITRE

Published: 2013-12-23

Updated: 2014-01-14

Type: CWE-352

Risk Information

CVSS v2

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM