Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2617-1 | samba security update |
EUVD |
EUVD-2013-0248 | Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions. |
Ubuntu USN |
USN-2922-1 | Samba vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T14:18:09.618Z
Reserved: 2012-12-06T00:00:00
Link: CVE-2013-0214
No data.
Status : Deferred
Published: 2013-02-02T20:55:03.147
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-0214
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN