CVE-2013-0196
Summary
| CVE | CVE-2013-0196 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-30 22:15:00 UTC |
| Updated | 2023-02-13 00:27:00 UTC |
| Description | A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Application | Redhat | Openshift | 1.2 | All | All | All |
| Application | Redhat | Openshift | 1.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/security/cve/CVE-2013-0196 | MISC | access.redhat.com | |
| CVE-2013-0196 - Red Hat Customer Portal | MISC | access.redhat.com | Third Party Advisory |
| Red Hat Customer Portal | MISC | access.redhat.com | |
| 901364 – (CVE-2013-0196) CVE-2013-0196 OpenShift Enterprise and Online vulnerable to CSRF attack with REST API | MISC | bugzilla.redhat.com | Exploit, Issue Tracking, Third Party Advisory |
| 901364 – (CVE-2013-0196) CVE-2013-0196 OpenShift Enterprise and Online vulnerable to CSRF attack with REST API | MISC | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.