First published: Wed Sep 21 2016(Updated: )
Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows remote attackers to hijack the authentication of unspecified victims for requests that create a resource via an HTTP POST request with a (1) missing or (2) crafted Content-Type header.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Jackrabbit | =2.4.0 | |
Apache Jackrabbit | =2.4.1 | |
Apache Jackrabbit | =2.4.2 | |
Apache Jackrabbit | =2.4.3 | |
Apache Jackrabbit | =2.4.4 | |
Apache Jackrabbit | =2.4.5 | |
Apache Jackrabbit | =2.6.0 | |
Apache Jackrabbit | =2.6.1 | |
Apache Jackrabbit | =2.6.2 | |
Apache Jackrabbit | =2.6.3 | |
Apache Jackrabbit | =2.6.4 | |
Apache Jackrabbit | =2.6.5 | |
Apache Jackrabbit | =2.8.0 | |
Apache Jackrabbit | =2.8.1 | |
Apache Jackrabbit | =2.8.2 | |
Apache Jackrabbit | =2.10.0 | |
Apache Jackrabbit | =2.10.1 | |
Apache Jackrabbit | =2.10.2 | |
Apache Jackrabbit | =2.10.3 | |
Apache Jackrabbit | =2.12.0 | |
Apache Jackrabbit | =2.12.1 | |
Apache Jackrabbit | =2.12.2 | |
Apache Jackrabbit | =2.12.3 | |
Apache Jackrabbit | =2.13.0 | |
Apache Jackrabbit | =2.13.1 | |
Apache Jackrabbit | =2.13.2 | |
Debian Debian Linux | =8.0 | |
maven/org.apache.jackrabbit:jackrabbit-webdav | >=2.13.0<2.13.3 | 2.13.3 |
maven/org.apache.jackrabbit:jackrabbit-webdav | >=2.12.0<2.12.4 | 2.12.4 |
maven/org.apache.jackrabbit:jackrabbit-webdav | >=2.10.0<2.10.4 | 2.10.4 |
maven/org.apache.jackrabbit:jackrabbit-webdav | >=2.8.0<2.8.3 | 2.8.3 |
maven/org.apache.jackrabbit:jackrabbit-webdav | >=2.6.0<2.6.6 | 2.6.6 |
maven/org.apache.jackrabbit:jackrabbit-webdav | >=2.4.0<2.4.6 | 2.4.6 |
Debian | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.