CVE-2023-6022: Cross-Site Request Forgery (CSRF) in prefecthq/prefect
An attacker is able to steal secrets and potentially gain remote code execution via CSRF using a self-hosted, open source Prefect API.
Other sources
Cross-Site Request Forgery (CSRF) in GitHub repository prefecthq/prefect prior to 2.16.5.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-6022?
CVE-2023-6022 is a vulnerability that allows an attacker to steal secrets and potentially gain remote code execution via Cross-Site Request Forgery (CSRF) using the Prefect API.
How severe is CVE-2023-6022?
CVE-2023-6022 has a severity level of 8.8 (high).
How does CVE-2023-6022 work?
CVE-2023-6022 allows an attacker to perform CSRF attacks by tricking a user into visiting a specially crafted website or clicking a malicious link, which then leads to the theft of secrets and potential remote code execution.
What software is affected by CVE-2023-6022?
The Prefect software is affected by CVE-2023-6022.
Is there a fix for CVE-2023-6022?
To fix CVE-2023-6022, it is recommended to update Prefect to the latest version or apply any available patches or security updates provided by the vendor.