CVE-2011-3636
published 2011-12-08CVE-2011-3636: Cross-site request forgery (CSRF) vulnerability in the management interface in FreeIPA before 2.1.4 allows remote attackers to hijack the authentication of…
PriorityP427medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
0.84%
53.7th percentile
Cross-site request forgery (CSRF) vulnerability in the management interface in FreeIPA before 2.1.4 allows remote attackers to hijack the authentication of administrators for requests that make configuration changes.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | freeipa | <= 2.1.3 | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
| redhat | freeipa | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
FreeIPA: CSRF vulnerability
vendor_redhat·2011-12-06·CVSS 6.8
CVE-2011-3636 [MEDIUM] CWE-352 FreeIPA: CSRF vulnerability
FreeIPA: CSRF vulnerability
Cross-site request forgery (CSRF) vulnerability in the management interface in FreeIPA before 2.1.4 allows remote attackers to hijack the authentication of administrators for requests that make configuration changes.
GHSA
GHSA-62x7-6pjw-j8fh: Cross-site request forgery (CSRF) vulnerability in the management interface in FreeIPA before 2
ghsa_unreviewed·2022-05-17
CVE-2011-3636 [MEDIUM] CWE-352 GHSA-62x7-6pjw-j8fh: Cross-site request forgery (CSRF) vulnerability in the management interface in FreeIPA before 2
Cross-site request forgery (CSRF) vulnerability in the management interface in FreeIPA before 2.1.4 allows remote attackers to hijack the authentication of administrators for requests that make configuration changes.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3636 FreeIPA: CSRF vulnerability
bugzilla·2011-10-20·CVSS 6.8
CVE-2011-3636 [MEDIUM] CVE-2011-3636 FreeIPA: CSRF vulnerability
CVE-2011-3636 FreeIPA: CSRF vulnerability
A Cross-Site Request Forgery (CSRF) flaw was found in FreeIPA due to a lack of checking the Referer Header in the server (it is not set in the CLI utilities). If a remote attacker could trick a user, who was logged into the FreeIPA management interface, into visiting a specially-crafted URL, the attacker could perform FreeIPA oonfiguration changes with the privileges of the logged in user.
Discussion:
Added Nalin as he is the maintainer of the certmonger package.
---
Created attachment 529392
Require a Referer in the server, send one in the clients
The xmlrpc-c api does not seem to provide a way to set arbitrary headers. It does allow you to set the user-agent string though, so we set that with an embedded line-feed (\n) and a Referer entry.
Bugzilla
flash-plugin: security bulletin APSB10-26
bugzilla·2010-11-04·CVSS 9.3
CVE-2010-3654 [CRITICAL] flash-plugin: security bulletin APSB10-26
flash-plugin: security bulletin APSB10-26
On 2011-11-04 Aboe plans to release an update for Adobe Flash Player, providing 10.1.102.64 and 9.0.289.0 to address multiple security issues allowing code execution. The flaws are described in the Adobe Security Bulletin ASPB10-26:
http://www.adobe.com/support/security/bulletins/apsb10-26.html
* This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-3654).
* This update resolves an input validation issue vulnerability that could lead to a bypass of cross-domain policy file restrictions with certain server encodings (CVE-2010-3636).
* This update resolves a memory corruption vulnerability that could lead to code execution (ActiveX only) (CVE-2010-3637).
* This update resolves an information disclosu
2011-12-08
Published