CyberRota Analysis
AI analysis pending.
CVE
CVE-2020-14369
Severity
MEDIUM
CVSS
6.3
EPSS
0.34%
Original NVD Description
This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a web application in which the user is currently authenticated. An attacker can make a forgery HTTP request to the server by crafting custom flash file which can force the user to perform state changing requests like provisioning VMs, running ansible playbooks and so forth.