Cross-site request forgery in MyFaces Core - CVE-2021-26296
Published: February 22, 2021 / Updated: February 25, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient CSRF protection mechanism. A remote attacker can guess the CSRF token, trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.
Affected software
IBM Tivoli Monitoring
IBM Cloud Transformation Advisor
IBM CICS TX on Cloud
IBM Cloud Orchestrator
How to mitigate CVE-2021-26296
IBM CICS TX on Cloud - addressed in versions 10.1.0.0 ifix6, 11.1.0.0 ifix1
Links to Public Exploits and PoC-codes
External References
- http://packetstormsecurity.com/files/161484/Apache-MyFaces-2.x-Cross-Site-Request-Forgery.html
- http://seclists.org/fulldisclosure/2021/Feb/66
- https://lists.apache.org/thread.html/r2b73e2356c6155e9ec78fdd8f72a4fac12f3e588014f5f535106ed9b%40%3Cannounce.apache.org%3E
- https://seclists.org/fulldisclosure/2021/Feb/66