CVE-2021-29995
09.06.2021, 15:15
A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.
Vendor | Product | Version |
---|---|---|
cloverdx | cloverdx | 𝑥 < 5.7.1 |
cloverdx | cloverdx | 5.8.0 ≤ 𝑥 < 5.8.2 |
cloverdx | cloverdx | 5.9.0 ≤ 𝑥 < 5.9.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References