PT-2021-15115 · Micro Focus · Micro Focus Application Automation Tools Plugin

Long Nguyen

·

Published

2021-04-08

·

Updated

2022-05-24

·

CVE-2021-22512

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Micro Focus Application Automation Tools Plugin versions 6.7 and earlier
Description The issue is related to a Cross-Site Request Forgery (CSRF) vulnerability. It affects the form validation process, allowing it to occur without proper permission checks. This could enable attackers with certain permissions to connect to specified URLs using specified usernames and passwords. The vulnerability also stems from the fact that form validation methods do not require POST requests, further facilitating CSRF attacks.
Recommendations For versions 6.7 and earlier, consider updating to version 6.8 or later, which requires POST requests and Overall/Administer permission for the affected form validation methods, thus mitigating the risk. As a temporary workaround, restrict access to the form validation methods to minimize the risk of exploitation. Additionally, ensure that only authorized personnel have Overall/Administer permission to further reduce the vulnerability's impact.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22512
GHSA-MWG2-3XPV-5V28

Affected Products

Micro Focus Application Automation Tools Plugin