Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 and 8.1.0.2 is affected by a cross-site request forgery vulnerability. A malicious user may potentially exploit this vulnerability to send unauthorized requests to the server on behalf of authenticated users of the application.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/103033 | third party advisory vdb entry |
http://seclists.org/fulldisclosure/2018/Mar/50 | third party advisory mailing list |
https://www.coresecurity.com/advisories/dell-emc-isilon-onefs-multiple-vulnerabilities | third party advisory exploit |
https://www.exploit-db.com/exploits/44039/ | third party advisory vdb entry exploit |