7.5
CVSSv3

CVE-2021-26296

Published: 19/02/2021 Updated: 02/06/2021
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 455
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an malicious user to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache myfaces

apache myfaces 2.3

apache myfaces 3.0.0

netapp oncommand insight -

Exploits

Apache MyFaces versions 2213 and below, 237 and below, 23-next-M4 and below, and 21 and below suffer from a cross site request forgery vulnerability ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [CSA-2021-001] Cross-Site Request Forgery in Apache MyFaces <!--X-Subject-Header-End--> <!--X-Head-of-Message--> Fro ...
<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2021-26296: Cross-Site Request Forgery (CSRF) vulnerability in Apache MyFaces <!--X-Subject-Header-End--> <!--X-Head-of-Me ...

Github Repositories

WebSphere Automation

ThinkLab-2257 IBM WebSphere Automation Think 2021 Lab instructions Lab Environment Once you login you will see 10 VMs (virtual machines) 3 are for lab infrastructure 3 for OCP (OpenShift) controllers 3 for OCP workers 1 for the lab (Student VM) WebSphere Automation is pre-installed in the OCP cluster hosted on the VMs You will be working on the Student VM only This VM i

Hands-on workshop for IBM WebSphere Automation solution that optimizes your WebSphere operations for security, resiliency and performance

ThinkLab-2257 IBM WebSphere Automation Think 2021 Lab instructions Lab Environment Once you log in, you will see 10 VMs (virtual machines) 3 are for lab infrastructure 3 for OCP (OpenShift) controllers 3 for OCP workers/compute 1 for the lab (Student VM) WebSphere Automation is pre-installed in the OCP cluster hosted on the VMs You will be working on the Student VM o