CVE-2017-15084: CSRF
Published Oct 6, 2017
·Updated
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
Affected Software
1 affected component
Rapid7 Metasploit<=4.14.1
Event History
Oct 6, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15084?
CVE-2017-15084 has a medium severity rating due to its potential for CSRF attacks.
2
How do I fix CVE-2017-15084?
To fix CVE-2017-15084, upgrade Rapid7 Metasploit to version 4.14.1 or later.
3
What type of attack is CVE-2017-15084 associated with?
CVE-2017-15084 is associated with a logout Cross-Site Request Forgery (CSRF) vulnerability.
4
What versions of Rapid7 Metasploit are affected by CVE-2017-15084?
All versions of Rapid7 Metasploit prior to 4.14.1 are affected by CVE-2017-15084.
5
Does CVE-2017-15084 impact web applications?
Yes, CVE-2017-15084 specifically impacts the web user interface of Rapid7 Metasploit.