CVE-2014-8246: CSRF
Published Dec 16, 2014
·Updated
Cross-site request forgery (CSRF) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Affected Software
1 affected component
Broadcom Release Automation<=4.7.1
Event History
Dec 16, 2014
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8246?
CVE-2014-8246 has a medium severity rating due to its potential for cross-site request forgery attacks.
2
How do I fix CVE-2014-8246?
To fix CVE-2014-8246, upgrade CA Release Automation to version 4.7.1 or later.
3
What type of vulnerability is CVE-2014-8246?
CVE-2014-8246 is a cross-site request forgery (CSRF) vulnerability.
4
Who is affected by CVE-2014-8246?
Users of CA Release Automation versions prior to 4.7.1 are affected by CVE-2014-8246.
5
What can attackers do with CVE-2014-8246?
Attackers can hijack the authentication of users through CVE-2014-8246, allowing unauthorized actions on their behalf.