CVE-2020-7304: DLP ePO extension - Cross-site request forgery
Published Aug 13, 2020
·Updated
Cross site request forgery vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attacker to embed a CRSF script via adding a new label.
Affected Software
3 affected components
McAfee Data Loss Prevention>=11.3.0<11.3.28
McAfee Data Loss Prevention>=11.4.0<11.4.200
McAfee Data Loss Prevention>=11.5.0<11.5.3
Event History
Aug 13, 2020
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-7304?
CVE-2020-7304 is a cross-site request forgery vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3.
2
How severe is CVE-2020-7304?
CVE-2020-7304 has a severity rating of 7.6 out of 10.
3
Which software versions are affected by CVE-2020-7304?
CVE-2020-7304 affects McAfee Data Loss Prevention (DLP) versions 11.3.0 to 11.3.28, 11.4.0 to 11.4.200, and 11.5.0 to 11.5.3.
4
How can an attacker exploit CVE-2020-7304?
An authenticated remote attacker can exploit CVE-2020-7304 by embedding a CSRF (cross-site request forgery) script via adding a new label.
5
Is there a fix for CVE-2020-7304?
Yes, updating McAfee Data Loss Prevention (DLP) to version 11.5.3 or later will fix CVE-2020-7304.