AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-14369

MEDIUM · CVSS 6.3 EPSS 0.34%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-12-02 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-14369
Severity
MEDIUM
CVSS
6.3
EPSS
0.34%

Original NVD Description

This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a web application in which the user is currently authenticated. An attacker can make a forgery HTTP request to the server by crafting custom flash file which can force the user to perform state changing requests like provisioning VMs, running ansible playbooks and so forth.