PT-2021-15115 · Micro Focus · Micro Focus Application Automation Tools Plugin
Long Nguyen
·
Published
2021-04-08
·
Updated
2022-05-24
·
CVE-2021-22512
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Micro Focus Application Automation Tools Plugin versions 6.7 and earlier
Description
The issue is related to a Cross-Site Request Forgery (CSRF) vulnerability. It affects the form validation process, allowing it to occur without proper permission checks. This could enable attackers with certain permissions to connect to specified URLs using specified usernames and passwords. The vulnerability also stems from the fact that form validation methods do not require POST requests, further facilitating CSRF attacks.
Recommendations
For versions 6.7 and earlier, consider updating to version 6.8 or later, which requires POST requests and Overall/Administer permission for the affected form validation methods, thus mitigating the risk. As a temporary workaround, restrict access to the form validation methods to minimize the risk of exploitation. Additionally, ensure that only authorized personnel have Overall/Administer permission to further reduce the vulnerability's impact.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Micro Focus Application Automation Tools Plugin