PT-2013-6012 · Apache · Apache Tomcat

CVE-2013-6357

·

Publicado

2013-11-13

·

Atualizado

2024-08-06

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 5.5.25 and earlier
Description A cross-site request forgery (CSRF) issue in the Manager application allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a "/manager/html/undeploy?path=" URI. The vendor disputes the significance of this report, stating that such attacks require a reckless system administrator.
Recommendations For Apache Tomcat versions 5.5.25 and earlier, consider disabling the Manager application until a patch is available to prevent exploitation of the CSRF vulnerability. Restrict access to the "/manager/html/undeploy" endpoint to minimize the risk of exploitation. Avoid using the path variable in the affected API endpoint until the issue is resolved.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-6357

Produtos afetados

Apache Tomcat