Description
ipl/web is a set of common web components for php projects. Some of the recent development by Icinga is, under certain circumstances, susceptible to cross site request forgery. (CSRF). All affected products, in any version, will be unaffected by this once `icinga-php-library` is upgraded. Version 0.10.1 includes a fix for this. It will be published as part of the `icinga-php-library` v0.14.1 release.
Published: 2024-08-05
Score: 3.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-2675 ipl/web is a set of common web components for php projects. Some of the recent development by Icinga is, under certain circumstances, susceptible to cross site request forgery. (CSRF). All affected products, in any version, will be unaffected by this once `icinga-php-library` is upgraded. Version 0.10.1 includes a fix for this. It will be published as part of the `icinga-php-library` v0.14.1 release.
Github GHSA Github GHSA GHSA-w9pg-7c3h-fc8j ipl/web's `ipl\Web\Common\CsrfCounterMeasure` is susceptible to CSRF
History

No history.

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-06T13:53:56.318Z

Reserved: 2024-07-22T13:57:37.136Z

Link: CVE-2024-41811

cve-icon Vulnrichment

Updated: 2024-08-06T13:53:51.693Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-05T21:15:38.673

Modified: 2024-08-06T16:30:24.547

Link: CVE-2024-41811

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses