CVE-2017-2093: Infoleak
Published Apr 28, 2017
·Updated
Cybozu Garoon 3.0.0 to 4.2.3 allow remote attackers to obtain tokens used for CSRF protection via unspecified vectors.
Affected Software
28 affected components
Cybozu Garoon=3.0.0
Cybozu Garoon=3.0.1
Cybozu Garoon=3.0.2
Cybozu Garoon=3.0.3
Cybozu Garoon=3.1.0
Cybozu Garoon=3.1.1
Cybozu Garoon=3.1.2
Cybozu Garoon=3.1.3
Cybozu Garoon=3.5.0
Cybozu Garoon=3.5.1
Cybozu Garoon=3.5.2
Cybozu Garoon=3.5.3
Cybozu Garoon=3.5.4
Cybozu Garoon=3.5.5
Cybozu Garoon=3.7.0
Cybozu Garoon=3.7.1
Cybozu Garoon=3.7.2
Cybozu Garoon=3.7.3
Cybozu Garoon=3.7.4
Cybozu Garoon=3.7.5
Cybozu Garoon=4.0.0
Cybozu Garoon=4.0.1
Cybozu Garoon=4.0.2
Cybozu Garoon=4.0.3
Cybozu Garoon=4.2.0
Cybozu Garoon=4.2.1
Cybozu Garoon=4.2.2
Cybozu Garoon=4.2.3
Event History
Apr 28, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-2093?
CVE-2017-2093 has been classified as a medium severity vulnerability due to its potential to allow remote exploitation.
2
How do I fix CVE-2017-2093?
To fix CVE-2017-2093, update Cybozu Garoon to version 4.2.4 or later where the vulnerability is patched.
3
What impact does CVE-2017-2093 have on affected systems?
CVE-2017-2093 can allow remote attackers to retrieve CSRF tokens, potentially leading to unauthorized actions on behalf of users.
4
Which versions are affected by CVE-2017-2093?
CVE-2017-2093 affects Cybozu Garoon versions 3.0.0 through 4.2.3.
5
Is my system vulnerable to CVE-2017-2093 if I am using an updated version?
If your system is running Cybozu Garoon version 4.2.4 or higher, it is not vulnerable to CVE-2017-2093.