PT-2016-7117 · Apache · Apache Jackrabbit

Lukas Reschke

·

Published

2016-09-21

·

Updated

2022-05-17

·

CVE-2016-6801

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Jackrabbit versions 2.4.x through 2.4.5 Apache Jackrabbit versions 2.6.x through 2.6.5 Apache Jackrabbit versions 2.8.x through 2.8.2 Apache Jackrabbit versions 2.10.x through 2.10.3 Apache Jackrabbit versions 2.12.x through 2.12.3 Apache Jackrabbit versions 2.13.x through 2.13.2
Description A cross-site request forgery (CSRF) issue exists in the CSRF content-type check in Jackrabbit-Webdav. This allows remote attackers to hijack the authentication of victims for requests that create a resource via an HTTP POST request with a missing or crafted Content-Type header.
Recommendations For Apache Jackrabbit versions 2.4.x through 2.4.5, update to version 2.4.6 or later. For Apache Jackrabbit versions 2.6.x through 2.6.5, update to version 2.6.6 or later. For Apache Jackrabbit versions 2.8.x through 2.8.2, update to version 2.8.3 or later. For Apache Jackrabbit versions 2.10.x through 2.10.3, update to version 2.10.4 or later. For Apache Jackrabbit versions 2.12.x through 2.12.3, update to version 2.12.4 or later. For Apache Jackrabbit versions 2.13.x through 2.13.2, update to version 2.13.3 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-6801
DLA-629-1
DSA-3679-1
GHSA-9FC7-RHQ3-WM7X

Affected Products

Apache Jackrabbit