CVE-2021-26296

CVSS v3.1 7.5 (High)
75% Progress
CVSS v2.0 5.1 (Medium)
51% Progress
EPSS 0.18 % (55th)
0.18% Progress
Affected Products 2
Advisories 1

In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.

Weaknesses
CWE-352
Cross-Site Request Forgery (CSRF)
CVE Status
PUBLISHED
CNA
Apache Software Foundation
Published Date
2021-02-19 09:15:13
(3 years ago)
Updated Date
2021-06-02 15:15:32
(3 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Myfaces from 2.2.0 version and 2.2.13 and prior versions cpe:2.3:a:apache:myfaces >= 2.2.0 <= 2.2.13
  Apache Myfaces from 2.3.0 version and 2.3.7 and prior versions cpe:2.3:a:apache:myfaces >= 2.3.0 <= 2.3.7
  Apache Myfaces 2.3 Next-m1 cpe:2.3:a:apache:myfaces:2.3:next-m1
  Apache Myfaces 2.3 Next-m2 cpe:2.3:a:apache:myfaces:2.3:next-m2
  Apache Myfaces 2.3 Next-m3 cpe:2.3:a:apache:myfaces:2.3:next-m3
  Apache Myfaces 2.3 Next-m4 cpe:2.3:a:apache:myfaces:2.3:next-m4
  Apache Myfaces 3.0.0 Rc1 cpe:2.3:a:apache:myfaces:3.0.0:rc1

Configuration #2

    CPE23 From Up To
  Netapp Oncommand Insight cpe:2.3:a:netapp:oncommand_insight:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...