← Back to CVE List

CVE-2020-14369

Published: 2020-12-02T15:15Z
Last Modified: 2024-11-21T05:03Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a web application in which the user is currently authenticated. An attacker can make a forgery HTTP request to the server by crafting custom flash file which can force the user to perform state changing requests like provisioning VMs, running ansible playbooks and so forth. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt