6.8

CVE-2012-4386

The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session attribute.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Struts Version 2.0.0
Apache ≫ Struts Version 2.0.1
Apache ≫ Struts Version 2.0.2
Apache ≫ Struts Version 2.0.3
Apache ≫ Struts Version 2.0.4
Apache ≫ Struts Version 2.0.5
Apache ≫ Struts Version 2.0.6
Apache ≫ Struts Version 2.0.7
Apache ≫ Struts Version 2.0.8
Apache ≫ Struts Version 2.0.9
Apache ≫ Struts Version 2.0.10
Apache ≫ Struts Version 2.0.11
Apache ≫ Struts Version 2.0.11.1
Apache ≫ Struts Version 2.0.11.2
Apache ≫ Struts Version 2.0.12
Apache ≫ Struts Version 2.0.13
Apache ≫ Struts Version 2.0.14
Apache ≫ Struts Version 2.1.0
Apache ≫ Struts Version 2.1.1
Apache ≫ Struts Version 2.1.2
Apache ≫ Struts Version 2.1.3
Apache ≫ Struts Version 2.1.4
Apache ≫ Struts Version 2.1.5
Apache ≫ Struts Version 2.1.6
Apache ≫ Struts Version 2.1.8
Apache ≫ Struts Version 2.1.8.1
Apache ≫ Struts Version 2.2.1
Apache ≫ Struts Version 2.2.1.1
Apache ≫ Struts Version 2.2.3
Apache ≫ Struts Version 2.2.3.1
Apache ≫ Struts Version 2.3.1
Apache ≫ Struts Version 2.3.1.1
Apache ≫ Struts Version 2.3.1.2
Apache ≫ Struts Version 2.3.3
Apache ≫ Struts Version 2.3.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.36% 0.878
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

http://secunia.com/advisories/50420
Vendor Advisory
http://struts.apache.org/2.x/docs/s2-010.html
Vendor Advisory
http://www.openwall.com/lists/oss-security/2012/09/01/4
http://www.openwall.com/lists/oss-security/2012/09/01/5
http://www.securityfocus.com/bid/55346
https://exchange.xforce.ibmcloud.com/vulnerabilities/78182
https://issues.apache.org/jira/browse/WW-3858