Cross-site request forgery in MyFaces Core - CVE-2021-26296

 

Cross-site request forgery in MyFaces Core - CVE-2021-26296

Published: February 22, 2021 / Updated: February 25, 2021


Vulnerability identifier: #VU50852
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-26296
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to insufficient CSRF protection mechanism. A remote attacker can guess the CSRF token, trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.


Affected software

MyFaces Core
IBM Tivoli Monitoring
IBM Cloud Transformation Advisor
IBM CICS TX on Cloud
IBM Cloud Orchestrator

How to mitigate CVE-2021-26296

Install update from vendor's website.

MyFaces Core - addressed in versions 2.2.14, 2.3-next-M5, 2.3.8, 3.0.0
IBM CICS TX on Cloud - addressed in versions 10.1.0.0 ifix6, 11.1.0.0 ifix1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins