Bug 1252885 (CVE-2015-5188, WFLY-2913)
Summary: | CVE-2015-5188 JBoss EAP: CSRF vulnerability in EAP & WildFly Web Console | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Vasyl Kaigorodov <vkaigoro> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | asantos, bilge, cdewolf, chazlett, dandread, darran.lofthouse, dhorton, jason.greene, jawilson, jpallich, lgao, myarboro, pslavice, rmarwaha, rsvoboda, security-response-team, slong, theute, ttarrant, twalsh, vtunka |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: |
It was discovered that when uploading a file using a multipart/form-data submission to the EAP Web Console, the Console was vulnerable to Cross-Site Request Forgery (CSRF). This meant that an attacker could use the flaw together with a forgery attack to make changes to an authenticated instance.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2021-10-21 00:47:40 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1253674 | ||
Bug Blocks: | 1252886, 1271191 |
Description
Vasyl Kaigorodov
2015-08-12 12:45:19 UTC
Harald Pehl <hpehl> updated the status of jira HAL-798 to Resolved Acknowledgement: This issue was discovered by Jason Greene of the Red Hat Middleware Engineering Team. This issue has been addressed in the following products: JBEAP 6.4.z for RHEL 6 Via RHSA-2015:1907 https://rhn.redhat.com/errata/RHSA-2015-1907.html This issue has been addressed in the following products: JBEAP 6.4.z for RHEL 6 Via RHSA-2015:1905 https://rhn.redhat.com/errata/RHSA-2015-1905.html This issue has been addressed in the following products: JBEAP 6.4.z for RHEL 5 Via RHSA-2015:1904 https://rhn.redhat.com/errata/RHSA-2015-1904.html This issue has been addressed in the following products: JBEAP 6.4.z for RHEL 7 Via RHSA-2015:1906 https://rhn.redhat.com/errata/RHSA-2015-1906.html Jason Greene <jason.greene> updated the status of jira WFCORE-594 to Resolved |