First published: Tue Sep 20 2011(Updated: )
JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approach.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
JasperReports Server Community Edition | =3.7.0 | |
JasperReports Server Community Edition | =3.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1911 is classified as a medium severity vulnerability due to its potential for cross-site request forgery attacks.
To mitigate CVE-2011-1911, upgrade JasperReports Server to version 3.7.2 or later.
CVE-2011-1911 allows attackers to execute unauthorized actions on behalf of legitimate users through CSRF attacks.
CVE-2011-1911 affects JasperReports Server versions 3.7.0 and 3.7.1.
Yes, CVE-2011-1911 can be exploited relatively easily through predictable parameter manipulation.