CVE-2012-6342: CSRF
Cross-site request forgery (CSRF) vulnerability in logout.action in Atlassian Confluence 3.4.6 allows remote attackers to hijack the authentication of administrators for requests that logout the user via a comment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6342?
CVE-2012-6342 is recognized as a medium severity vulnerability due to its potential for CSRF attacks against administrator sessions.
How do I fix CVE-2012-6342?
To fix CVE-2012-6342, upgrade Atlassian Confluence to a version that addresses this CSRF vulnerability.
Who is affected by CVE-2012-6342?
CVE-2012-6342 affects users of Atlassian Confluence version 3.4.6, particularly those with administrative privileges.
What type of vulnerability is CVE-2012-6342?
CVE-2012-6342 is a Cross-Site Request Forgery (CSRF) vulnerability, allowing attackers to perform unauthorized actions on behalf of authenticated users.
What can attackers achieve with CVE-2012-6342?
Attackers can use CVE-2012-6342 to log out administrators from their sessions without their consent, disrupting their activities.