Project

General

Custom queries

Profile

Actions

Bug #6999

closed

CVE-2014-3590 - User logout susceptible to CSRF attack

Added by Dominic Cleal over 10 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
Normal
Category:
Security
Target version:
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

I have created page on completely different machine with:

  1. cat /var/www/html/pub/aaa.html
    <html>
    <body>
    <img src='https://foreman.example.com/users/logout&#039;/>
    </body>
    </html>

and once I have loaded it, I was logged-off from webUI.

Reported by Jan Hutař of Red Hat.


Related issues 2 (0 open2 closed)

Related to Foreman - Bug #7736: Change to prevent unauthenticated requests for CSRF modified login behaviour as wellRejected09/29/2014Actions
Related to Foreman - Bug #7737: Change for issue 6999 broke logout for PAM-based (intercept) authenticationClosed09/29/2014Actions
#1

Updated by Dominic Cleal over 10 years ago

  • Subject changed from User logout susceptible to CSRF attack to CVE-2014-3590 - User logout susceptible to CSRF attack
#2

Updated by Anonymous over 10 years ago

  • Target version changed from 1.7.5 to 1.7.4
#3

Updated by Shlomi Zadok over 10 years ago

  • Assignee set to Shlomi Zadok
#6

Updated by Dominic Cleal over 10 years ago

  • Status changed from New to Assigned
#7

Updated by Shlomi Zadok over 10 years ago

  • Status changed from Assigned to New
#9

Updated by Dominic Cleal over 10 years ago

  • Translation missing: en.field_release changed from 20 to 22
#10

Updated by Daniel Lobato Garcia over 10 years ago

  • Assignee changed from Shlomi Zadok to Daniel Lobato Garcia
#11

Updated by The Foreman Bot over 10 years ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/theforeman/foreman/pull/1738 added
  • Pull request deleted ()
#12

Updated by Anonymous over 10 years ago

  • Target version changed from 1.7.4 to 1.7.3
#13

Updated by Daniel Lobato Garcia over 10 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100
#14

Updated by Dominic Cleal over 10 years ago

  • Related to Bug #7736: Change to prevent unauthenticated requests for CSRF modified login behaviour as well added
#15

Updated by Marek Hulán over 10 years ago

  • Related to Bug #7737: Change for issue 6999 broke logout for PAM-based (intercept) authentication added
Actions

Also available in: Atom PDF