Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-26296

Опубликовано: 18 фев. 2021
Источник: redhat
CVSS3: 7.5

Описание

In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.

Отчет

Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it was deprecated as of RHOSP 14 and is only receiving security fixes for Important and Critical flaws.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7jsf-impl-myfacesWill not fix
Red Hat JBoss Enterprise Application Platform 6myfaces-implOut of support scope
Red Hat JBoss Enterprise Application Platform 7myfaces-implNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packmyfaces-implNot affected
Red Hat OpenStack Platform 13 (Queens)opendaylightWill not fix
Red Hat Process Automation 7jsf-impl-myfacesWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-352
https://bugzilla.redhat.com/show_bug.cgi?id=1930409myfaces: Cross-site request forgery vulnerability in Apache MyFaces

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 5 лет назад

In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.

github
больше 4 лет назад

Cryptographically weak CSRF tokens in Apache MyFaces

7.5 High

CVSS3