Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-26296

Опубликовано: 19 фев. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5.1
EPSS Низкий

Описание

In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:myfaces:*:*:*:*:*:*:*:*
Версия от 2.2.0 (включая) до 2.2.13 (включая)
cpe:2.3:a:apache:myfaces:*:*:*:*:*:*:*:*
Версия от 2.3.0 (включая) до 2.3.7 (включая)
cpe:2.3:a:apache:myfaces:2.3:next-m1:*:*:*:*:*:*
cpe:2.3:a:apache:myfaces:2.3:next-m2:*:*:*:*:*:*
cpe:2.3:a:apache:myfaces:2.3:next-m3:*:*:*:*:*:*
cpe:2.3:a:apache:myfaces:2.3:next-m4:*:*:*:*:*:*
cpe:2.3:a:apache:myfaces:3.0.0:rc1:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*

EPSS

Процентиль: 64%
0.00461
Низкий

7.5 High

CVSS3

5.1 Medium

CVSS2

Дефекты

CWE-352
CWE-352

Связанные уязвимости

CVSS3: 7.5
redhat
почти 5 лет назад

In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.

github
больше 4 лет назад

Cryptographically weak CSRF tokens in Apache MyFaces

EPSS

Процентиль: 64%
0.00461
Низкий

7.5 High

CVSS3

5.1 Medium

CVSS2

Дефекты

CWE-352
CWE-352