First published: Sat Sep 17 2022(Updated: )
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.5.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Ikus-soft Rdiffweb | <2.4.5 | |
pip/rdiffweb | <2.4.5 | 2.4.5 |
<2.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-3232.
The severity of CVE-2022-3232 is medium with a severity value of 4.3.
The affected software for CVE-2022-3232 is Ikus-soft Rdiffweb version up to but excluding 2.4.5.
The CSRF vulnerability in GitHub repository ikus060/rdiffweb prior to 2.4.5 can allow attackers to perform malicious actions on behalf of authenticated users.
To fix the CSRF vulnerability in GitHub repository ikus060/rdiffweb prior to 2.4.5, update to version 2.4.5 or newer.