CVE-2011-0650: CSRF
Published Jan 28, 2011
·Updated
Cross-site request forgery (CSRF) vulnerability in Greenbone Security Assistant (GSA) before 2.0+rc3 allows remote attackers to hijack the authentication of users for requests that send email via an OMP request to OpenVAS Manager. NOTE: this issue can be leveraged to bypass authentication requirements for exploiting CVE-2011-0018.
Affected Software
1 affected component
Greenbone Greenbone Security Assistant<=2.0
Event History
Jan 28, 2011
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0650?
CVE-2011-0650 is classified as a medium severity vulnerability.
2
How do I fix CVE-2011-0650?
To fix CVE-2011-0650, upgrade Greenbone Security Assistant to version 2.0+rc3 or later.
3
What impact does CVE-2011-0650 have on users?
CVE-2011-0650 allows remote attackers to hijack user authentication and send unauthorized email requests.
4
Is CVE-2011-0650 still a concern for current Greenbone users?
CVE-2011-0650 is a concern only for users running versions prior to 2.0+rc3.
5
Can CVE-2011-0650 be exploited remotely?
Yes, CVE-2011-0650 can be exploited remotely without physical access to the system.