First published: Wed Sep 21 2022(Updated: )
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Ikus-soft Rdiffweb | <2.4.6 | |
Ikus-soft Rdiffweb | =2.4.6 | |
pip/rdiffweb | <2.4.6 | 2.4.6 |
<2.4.6 | ||
=2.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3233 is a vulnerability categorized as Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to version 2.4.6.
The severity level of CVE-2022-3233 is medium with a CVSS score of 4.3.
Ikus-soft Rdiffweb versions prior to 2.4.6 are affected by CVE-2022-3233.
To fix CVE-2022-3233, it is recommended to upgrade to version 2.4.6 or above of Ikus-soft Rdiffweb.
More information about CVE-2022-3233 can be found at the following references: [GitHub Commit](https://github.com/ikus060/rdiffweb/commit/18a5aabd48fa6d2d2771a25f95610c28a1a097ca) and [Huntr.dev](https://huntr.dev/bounties/5ec206e0-eca0-4957-9af4-fdd9185d1db3).