CVE-2022-24947: Apache JSPWiki CSRF Account Takeover
Published Feb 25, 2022
·Updated
Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later.
Affected Software
1 affected component
Apache JSPWiki<2.11.2
Event History
Feb 25, 2022
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-24947.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Apache JSPWiki user preferences form is vulnerable to CSRF attacks which can lead to account takeover.'
3
What is the severity of CVE-2022-24947?
The severity of CVE-2022-24947 is high (8.8).
4
How does CVE-2022-24947 affect Apache JSPWiki?
CVE-2022-24947 affects Apache JSPWiki version 2.11.2 and earlier.
5
How can Apache JSPWiki users protect themselves from CVE-2022-24947?
Apache JSPWiki users should upgrade to version 2.11.2 or later to protect themselves from CVE-2022-24947.