CVE-2013-1639: CSRF
Published Feb 8, 2013
·Updated
Opera before 12.13 does not send CORS preflight requests in all required cases, which allows remote attackers to bypass a CSRF protection mechanism via a crafted web site that triggers a CORS request.
Affected Software
8 affected components
opera Opera Browser<=12.12
opera Opera Browser=12.00
opera Opera Browser=12.00-beta
opera Opera Browser=12.01
opera Opera Browser=12.02
opera Opera Browser=12.10
opera Opera Browser=12.10-beta
opera Opera Browser=12.11
Event History
Feb 8, 2013
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1639?
CVE-2013-1639 is classified as a medium severity vulnerability.
2
How do I fix CVE-2013-1639?
To fix CVE-2013-1639, users should update their Opera browser to version 12.13 or later.
3
What type of attack does CVE-2013-1639 allow?
CVE-2013-1639 allows attackers to bypass Cross-Site Request Forgery (CSRF) protection mechanisms.
4
In which versions of Opera is CVE-2013-1639 present?
CVE-2013-1639 affects Opera browser versions prior to 12.13.
5
What is the nature of the vulnerability in CVE-2013-1639?
CVE-2013-1639 is related to improper handling of CORS preflight requests.