CVE-2014-7809: CSRF
Published Dec 10, 2014
·Updated
Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mechanism.
Affected Software
52 affected componentsFixes available
maven/org.apache.struts:struts2-core<2.3.20
2.3.20
Apache struts=2.0.0
Apache struts=2.0.1
Apache struts=2.0.2
Apache struts=2.0.3
Apache struts=2.0.4
Apache struts=2.0.5
Apache struts=2.0.6
Apache struts=2.0.7
Apache struts=2.0.8
Apache struts=2.0.9
Apache struts=2.0.10
Apache struts=2.0.11
Apache struts=2.0.11.1
Apache struts=2.0.11.2
Apache struts=2.0.12
Apache struts=2.0.13
Apache struts=2.0.14
Apache struts=2.1.0
Apache struts=2.1.1
Apache struts=2.1.2
Apache struts=2.1.3
Apache struts=2.1.4
Apache struts=2.1.5
Apache struts=2.1.6
Apache struts=2.1.8
Apache struts=2.1.8.1
Apache struts=2.2.1
Apache struts=2.2.1.1
Apache struts=2.2.3
Apache struts=2.2.3.1
Apache struts=2.3.1
Apache struts=2.3.1.1
Apache struts=2.3.1.2
Apache struts=2.3.3
Apache struts=2.3.4
Apache struts=2.3.4.1
Apache struts=2.3.7
Apache struts=2.3.8
Apache struts=2.3.12
Apache struts=2.3.14
Apache struts=2.3.14.1
Apache struts=2.3.14.2
Apache struts=2.3.14.3
Apache struts=2.3.15
Apache struts=2.3.15.1
Apache struts=2.3.15.2
Apache struts=2.3.15.3
Apache struts=2.3.16
Apache struts=2.3.16.1
Apache struts=2.3.16.2
Apache struts=2.3.16.3
Event History
Dec 10, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
May 14, 2022
Advisory Published
02:50 AM
Frequently Asked Questions
1
What is the severity of CVE-2014-7809?
CVE-2014-7809 is considered a high severity vulnerability due to the potential for unauthorized CSRF attacks.
2
How do I fix CVE-2014-7809?
To fix CVE-2014-7809, upgrade your Apache Struts installation to version 2.3.20 or later.
3
What are the affected Apache Struts versions for CVE-2014-7809?
CVE-2014-7809 affects Apache Struts versions 2.0.0 through 2.3.19.
4
Can CVE-2014-7809 be exploited remotely?
Yes, CVE-2014-7809 allows remote attackers to exploit the vulnerability and bypass CSRF protections.
5
What is the impact of not addressing CVE-2014-7809?
Failing to address CVE-2014-7809 can lead to unauthorized actions being performed on behalf of users without their knowledge.