Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-84m7-cxq5-q9xc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.

A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.

EPSS

Процентиль: 25%
0.00085
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 7.1
redhat
больше 5 лет назад

A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.

CVSS3: 7.1
nvd
больше 4 лет назад

A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.

EPSS

Процентиль: 25%
0.00085
Низкий

Дефекты

CWE-352