Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-8764

Опубликовано: 27 мар. 2018
Источник: debian
EPSS Низкий

Описание

Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ldap-account-managerfixed6.3-1package
ldap-account-managerfixed5.5-1+deb9u1stretchpackage
ldap-account-managernot-affectedjessiepackage
ldap-account-managernot-affectedwheezypackage

Примечания

  • https://www.ldap-account-manager.org/lamcms/node/354

  • https://github.com/LDAPAccountManager/lam/commit/993751c7ff0faa07b7c028295152cf9c20349688

EPSS

Процентиль: 57%
0.00356
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 8 лет назад

Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.

CVSS3: 8.8
nvd
почти 8 лет назад

Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.

CVSS3: 8.8
github
больше 3 лет назад

Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.

EPSS

Процентиль: 57%
0.00356
Низкий