CVE-2021-26296

Description

In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.321

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in IBM WebSphere 9.0.5.8Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.5.5.20Windows
Vulnerabilities CVE-2021-26296 are fixed in IBM WebSphere 21.0.0.4Windows
Vulnerabilities CVE-2021-26296 are fixed in Apache-myfaces-core-module 2.0.25Windows
Vulnerabilities CVE-2021-26296 are fixed in Apache-myfaces-core-module 2.1.19Windows
Vulnerabilities CVE-2021-26296 are fixed in Apache-myfaces-core-module 2.2.14Windows
Vulnerabilities CVE-2021-26296 are fixed in Apache-myfaces-core-module 2.3.8Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
Multiple Vulnerabilities are affected in IBM TXSeries for Multiplatforms 8.2.0.2Windows
Vulnerabilities CVE-2019-4441,CVE-2021-26296 are affected in IBM TXSeries for Multiplatforms 8.1.0.3Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 20.0Windows
Multiple Vulnerabilities are affected in IBM Tivoli Application Dependency Discovery Manager 7.3.0.8Windows
Vulnerabilities CVE-2021-26296,CVE-2021-39038,CVE-2022-24839 are affected in IBM TXSeries for Multiplatforms 9.1.0.2Windows
Vulnerabilities CVE-2021-26296 are fixed in Apache-myfaces-core-module for Linux 2.0.25Linux
Vulnerabilities CVE-2021-26296 are fixed in Apache-myfaces-core-module for Linux 2.1.19Linux
Vulnerabilities CVE-2021-26296 are fixed in Apache-myfaces-core-module for Linux 2.2.14Linux
Vulnerabilities CVE-2021-26296 are fixed in Apache-myfaces-core-module for Linux 2.3.8Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234