CVE-2013-6443: Red Hat Cloudforms
Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.
CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destructive action in a request.
Affected products
- Red Hat Cloudforms: version 3.0 only
- Red Hat Cloudforms 3.0 Management Engine: up to and including 5.2.1; version 5.2 only
Published 2014-01-23. Last modified 2026-06-17.