Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0800 | Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later. |
Github GHSA |
GHSA-4284-x26r-4hhc | Cross Site Request Forgery in Apache JSPWiki |
Fixes
Solution
No solution given by the vendor.
Workaround
Installations >= 2.7.0 can also enable user management workflows' manual approval to mitigate the issue.
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T04:29:01.578Z
Reserved: 2022-02-10T00:00:00.000Z
Link: CVE-2022-24947
No data.
Status : Modified
Published: 2022-02-25T09:15:07.007
Modified: 2024-11-21T06:51:26.323
Link: CVE-2022-24947
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA