First published: Thu Sep 15 2022(Updated: )
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.3.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Ikus-soft Rdiffweb | <2.4.3 | |
pip/rdiffweb | <2.4.3 | 2.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-3221 is high.
CVE-2022-3221 is a Cross-Site Request Forgery (CSRF) vulnerability in GitHub repository ikus060/rdiffweb prior to version 2.4.3.
CVE-2022-3221 allows an attacker to perform unauthorized actions on behalf of an authenticated user in ikus060/rdiffweb.
To fix CVE-2022-3221, update the ikus060/rdiffweb repository to version 2.4.3 or later.
You can find more information about CVE-2022-3221 at the following references: [GitHub Commit](https://github.com/ikus060/rdiffweb/commit/9125f5a2d918fed0f3fc1c86fa94cd1779ed9f73), [Huntr Dev](https://huntr.dev/bounties/1fa1aac9-b16a-4a70-a7da-960b3908ae1d).