CVE-2010-0713: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack the authentication of an administrator for (1) requests that reset user passwords via zport/dmd/ZenUsers/admin, and (2) requests that change user commands, which allows for remote execution of system commands via zport/dmd/userCommands/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0713?
CVE-2010-0713 is considered a medium severity vulnerability affecting multiple versions of Zenoss.
How do I fix CVE-2010-0713?
To remediate CVE-2010-0713, upgrade Zenoss to version 2.5 or later, which addresses the CSRF vulnerabilities.
What types of attacks does CVE-2010-0713 allow?
CVE-2010-0713 allows remote attackers to perform actions such as resetting user passwords and changing user commands by hijacking administrator authentication.
Which versions of Zenoss are affected by CVE-2010-0713?
CVE-2010-0713 affects Zenoss versions 2.3.0 through 2.4.5, including version 2.3.3.
Is CVE-2010-0713 related to cross-site request forgery?
Yes, CVE-2010-0713 specifically involves multiple cross-site request forgery (CSRF) vulnerabilities.