In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: microfocus
Published: 2014-03-26T00:00:00
Updated: 2021-01-06T16:15:36
Reserved: 2013-12-28T00:00:00
Link: CVE-2014-0594
JSON object: View
NVD Information
Status : Modified
Published: 2018-06-08T17:29:00.443
Modified: 2023-11-07T02:18:24.333
Link: CVE-2014-0594
JSON object: View
Redhat Information
No data.
CWE