CVE-2021-29238: CSRF
Published May 3, 2021
·Updated
CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF).
Affected Software
1 affected component
CODESYS Automation Server<1.16.0
Event History
May 3, 2021
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-29238?
CVE-2021-29238 is categorized as a cross-site request forgery (CSRF) vulnerability, which can lead to unauthorized actions within the application.
2
How do I fix CVE-2021-29238?
To address CVE-2021-29238, upgrade your CODESYS Automation Server to version 1.16.0 or later.
3
What software is affected by CVE-2021-29238?
CVE-2021-29238 affects CODESYS Automation Server versions prior to 1.16.0.
4
What kind of attack does CVE-2021-29238 enable?
CVE-2021-29238 enables attackers to perform unauthorized actions on behalf of authenticated users due to CSRF vulnerabilities.
5
Is there a patch available for CVE-2021-29238?
Yes, a patch is available by upgrading to CODESYS Automation Server version 1.16.0 or later.