CVE-2012-4386
The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration…
Does this matter?
Lower severity and a low EPSS score (3.36%). Track it; it rarely justifies an emergency change on its own.
Description
The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session attribute.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 3.36% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- apache/struts
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/50420Vendor Advisory
- http://struts.apache.org/2.x/docs/s2-010.htmlVendor Advisory
- http://www.openwall.com/lists/oss-security/2012/09/01/4
- http://www.openwall.com/lists/oss-security/2012/09/01/5
- http://www.securityfocus.com/bid/55346
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78182
- https://issues.apache.org/jira/browse/WW-3858
- http://secunia.com/advisories/50420Vendor Advisory
- http://struts.apache.org/2.x/docs/s2-010.htmlVendor Advisory
- http://www.openwall.com/lists/oss-security/2012/09/01/4
- http://www.openwall.com/lists/oss-security/2012/09/01/5
- http://www.securityfocus.com/bid/55346
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78182
- https://issues.apache.org/jira/browse/WW-3858
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.