First published: Thu Dec 22 2022(Updated: )
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.5.4.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Ikus-soft Rdiffweb | <2.5.4 | |
pip/rdiffweb | <2.5.4 | 2.5.4 |
<2.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4646 is a Cross-Site Request Forgery (CSRF) vulnerability in the GitHub repository ikus060/rdiffweb prior to version 2.5.4.
CVE-2022-4646 has a severity keyword of medium and a severity value of 6.5.
CVE-2022-4646 affects the Ikus-soft Rdiffweb software version prior to 2.5.4 by allowing Cross-Site Request Forgery attacks.
To fix CVE-2022-4646, upgrade the Ikus-soft Rdiffweb software to version 2.5.4 or newer.
You can find more information about CVE-2022-4646 at the following references: [GitHub commit](https://github.com/ikus060/rdiffweb/commit/e6f0d8002129be90fe82fa3e3ea0a6942caba398) and [Huntr bounty](https://huntr.dev/bounties/17bc1b0f-1f5c-432f-88e4-c9866ccf6e10).