CVE-2021-26296
Published Feb 19, 2021
Last updated 3 years ago
Overview
- Description
- In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.
- Source
- security@apache.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 5.9
- Exploitability score
- 1.6
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 5.1
- Impact score
- 6.4
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:P/I:P/A:P
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:apache:myfaces:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "43C2311F-12BF-4C37-8FF2-B5F555888D92", "versionEndIncluding": "2.2.13", "versionStartIncluding": "2.2.0" }, { "criteria": "cpe:2.3:a:apache:myfaces:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ACA9DF3E-01A7-49C4-9E63-1CA07DA1A2C2", "versionEndIncluding": "2.3.7", "versionStartIncluding": "2.3.0" }, { "criteria": "cpe:2.3:a:apache:myfaces:2.3:next-m1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EF54DDD0-74AA-494B-9F69-C1BA5A208B1F" }, { "criteria": "cpe:2.3:a:apache:myfaces:2.3:next-m2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6DBA33A5-97A2-45D4-AAAC-AD6A05888656" }, { "criteria": "cpe:2.3:a:apache:myfaces:2.3:next-m3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CBE81BF3-66DB-4BD7-A767-547A727CF9B3" }, { "criteria": "cpe:2.3:a:apache:myfaces:2.3:next-m4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3A377CFB-B073-4B74-9CE9-0D09A08FCFCF" }, { "criteria": "cpe:2.3:a:apache:myfaces:3.0.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7CD2AAA3-C1C0-43B2-BD90-742B0B85CD65" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F1BE6C1F-2565-4E97-92AA-16563E5660A5" } ], "operator": "OR" } ] } ]