CVE-2013-6443: Red Hat Cloudforms

Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.

CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request.

Affected products

  • Red Hat Cloudforms: version 3.0 only
  • Red Hat Cloudforms 3.0 Management Engine: up to and including 5.2.1; version 5.2 only

Published 2014-01-23. Last modified 2026-06-17.