CVE-2021-26296
19.02.2021, 09:15
In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.
Vendor | Product | Version |
---|---|---|
apache | myfaces | 2.2.0 ≤ 𝑥 ≤ 2.2.13 |
apache | myfaces | 2.3.0 ≤ 𝑥 ≤ 2.3.7 |
apache | myfaces | 2.3:next-m1 |
apache | myfaces | 2.3:next-m2 |
apache | myfaces | 2.3:next-m3 |
apache | myfaces | 2.3:next-m4 |
apache | myfaces | 3.0.0:rc1 |
netapp | oncommand_insight | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References