PT-2014-1948 · Apache · Apache Struts

Publicado

2014-12-10

·

Atualizado

2022-05-14

·

CVE-2014-7809

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Struts versions 2.0.0 through 2.3.x before 2.3.20
Description The issue is related to the use of predictable s:token/ values, which allows remote attackers to bypass the CSRF protection mechanism. This can enable a remote attacker to perform a CSRF attack.
Recommendations For Apache Struts versions 2.0.0 through 2.3.x before 2.3.20, update to version 2.3.20 or later to resolve the issue. As a temporary workaround, consider implementing additional CSRF protection measures to minimize the risk of exploitation.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09977
CVE-2014-7809
GHSA-H4V9-JF2R-9H6M

Produtos afetados

Apache Struts