CVE-2013-0214: CSRF
Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0214?
CVE-2013-0214 has been assessed as a moderate severity vulnerability allowing attackers to hijack user authentication.
How do I fix CVE-2013-0214?
To fix CVE-2013-0214, upgrade Samba to version 3.5.21, 3.6.12 or later, or 4.0.2 or later.
Which versions of Samba are affected by CVE-2013-0214?
CVE-2013-0214 affects Samba versions 3.x before 3.5.21 and 3.6.x before 3.6.12, as well as 4.x before 4.0.2.
What type of vulnerability is CVE-2013-0214?
CVE-2013-0214 is a Cross-site request forgery (CSRF) vulnerability.
Can CVE-2013-0214 be exploited remotely?
Yes, CVE-2013-0214 can be exploited remotely if an attacker has knowledge of the user's password.