Lucene search

K
redhatcveRedhat.comRH:CVE-2017-2653
HistoryMar 14, 2017 - 5:49 p.m.

CVE-2017-2653

2017-03-1417:49:33
redhat.com
access.redhat.com
10

0.001 Low

EPSS

Percentile

38.3%

A number of unused delete routes are present in CloudForms which can be accessed via GET requests instead of just POST requests. This could allow an attacker to bypass the protect_from_forgery XSRF protection causing the routes to be used. This attack would require additional cross-site scripting or similar attacks in order to execute.

0.001 Low

EPSS

Percentile

38.3%

Related for RH:CVE-2017-2653