VulnerabilityModified
CVE-2018-7634
Lack of CSRF attack mitigation while changing an e-mail address makes it possible to abuse the functionality by attackers.
HIGH 8.8EPSS 0.79%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.79%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Enalean Tuleap 9.17. Lack of CSRF attack mitigation while changing an e-mail address makes it possible to abuse the functionality by attackers. By making a CSRF attack, an attacker could make a victim change his registered e-mail address on the application, leading to account takeover.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.79% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- enalean/tuleap
- Source
- cve@mitre.org
References
- https://github.com/Enalean/tuleap/commit/0843c046eee54b16ec6a7753c575838212770189Patch
- https://mustafairan.wordpress.com/2018/03/05/tuleap-mail-change-csrf-vulnerability-leads-to-account-takeover/Exploit, Patch, Third Party Advisory
- https://tuleap.net/plugins/git/tuleap/tuleap/stable?p=tuleap%2Fstable.git&a=commit&h=d6701289ae55de900929ff0f66313fa9771a198dIssue Tracking, Patch, Vendor Advisory
- https://tuleap.net/plugins/tracker/?aid=11217Patch, Vendor Advisory
- https://twitter.com/Mustafaran/status/970745812887199744Exploit, Third Party Advisory
- https://github.com/Enalean/tuleap/commit/0843c046eee54b16ec6a7753c575838212770189Patch
- https://mustafairan.wordpress.com/2018/03/05/tuleap-mail-change-csrf-vulnerability-leads-to-account-takeover/Exploit, Patch, Third Party Advisory
- https://tuleap.net/plugins/git/tuleap/tuleap/stable?p=tuleap%2Fstable.git&a=commit&h=d6701289ae55de900929ff0f66313fa9771a198dIssue Tracking, Patch, Vendor Advisory
- https://tuleap.net/plugins/tracker/?aid=11217Patch, Vendor Advisory
- https://twitter.com/Mustafaran/status/970745812887199744Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.