Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-84m7-cxq5-q9xc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.

A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.

EPSS

Процентиль: 37%
0.00445
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 7.1
redhat
около 6 лет назад

A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.

CVSS3: 7.1
nvd
около 5 лет назад

A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.

EPSS

Процентиль: 37%
0.00445
Низкий

Дефекты

CWE-352