PT-2022-21433 · Rdiffweb · Rdiffweb

Published

2022-09-22

·

Updated

2022-09-23

·

CVE-2022-3267

CVSS v3.1

6.8

Medium

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions rdiffweb versions prior to 2.4.6
Description The issue is related to Cross-Site Request Forgery (CSRF) in the repository settings. A malicious user can change the settings of a repository by sending a URL to the victim.
Recommendations For versions prior to 2.4.6, update to version 2.4.6 to resolve the issue. As a temporary workaround, consider restricting access to the repository settings to minimize the risk of exploitation.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-3267
GHSA-74J6-3HH4-W3F5
PYSEC-2022-284

Affected Products

Rdiffweb