Project

General

Profile

Actions

Bug #6999

closed

CVE-2014-3590 - User logout susceptible to CSRF attack

Added by Dominic Cleal over 9 years ago. Updated almost 6 years ago.

Status:
Closed
Priority:
Normal
Category:
Security
Target version:
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

I have created page on completely different machine with:

  1. cat /var/www/html/pub/aaa.html
    <html>
    <body>
    <img src='https://foreman.example.com/users/logout&#039;/>
    </body>
    </html>

and once I have loaded it, I was logged-off from webUI.

Reported by Jan Hutař of Red Hat.


Related issues 2 (0 open2 closed)

Related to Foreman - Bug #7736: Change to prevent unauthenticated requests for CSRF modified login behaviour as wellRejected09/29/2014Actions
Related to Foreman - Bug #7737: Change for issue 6999 broke logout for PAM-based (intercept) authenticationClosed09/29/2014Actions
Actions

Also available in: Atom PDF