CVE-2016-6801

Description

Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows remote attackers to hijack the authentication of unspecified victims for requests that create a resource via an HTTP POST request with a (1) missing or (2) crafted Content-Type header.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.36

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-6801 are fixed in Apache-jackrabbit-webdav 2.4.6Windows
Vulnerabilities CVE-2016-6801 are fixed in Apache-jackrabbit-webdav 2.6.6Windows
Vulnerabilities CVE-2016-6801 are fixed in Apache-jackrabbit-webdav 2.8.3Windows
Vulnerabilities CVE-2016-6801 are fixed in Apache-jackrabbit-webdav 2.10.4Windows
Vulnerabilities CVE-2016-6801 are fixed in Apache-jackrabbit-webdav 2.12.4Windows
Vulnerabilities CVE-2016-6801 are fixed in Apache-jackrabbit-webdav 2.13.3Windows
Vulnerabilities CVE-2016-6801 are fixed in Apache-jackrabbit-webdav for Linux 2.4.6Linux
Vulnerabilities CVE-2016-6801 are fixed in Apache-jackrabbit-webdav for Linux 2.6.6Linux
Vulnerabilities CVE-2016-6801 are fixed in Apache-jackrabbit-webdav for Linux 2.8.3Linux
Vulnerabilities CVE-2016-6801 are fixed in Apache-jackrabbit-webdav for Linux 2.10.4Linux
Vulnerabilities CVE-2016-6801 are fixed in Apache-jackrabbit-webdav for Linux 2.12.4Linux
Vulnerabilities CVE-2016-6801 are fixed in Apache-jackrabbit-webdav for Linux 2.13.3Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234