CVE-2016-6801
published 2016-09-21CVE-2016-6801: Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before…
PriorityP346high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.29%
81.3th percentile
Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows remote attackers to hijack the authentication of unspecified victims for requests that create a resource via an HTTP POST request with a (1) missing or (2) crafted Content-Type header.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2016-6801: jackrabbit - Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check i...
vendor_debian·2016·CVSS 8.8
CVE-2016-6801 [HIGH] CVE-2016-6801: jackrabbit - Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check i...
Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows remote attackers to hijack the authentication of unspecified victims for requests that create a resource via an HTTP POST request with a (1) missing or (2) crafted Content-Type header.
Scope: local
bookworm: resolved (fixed in 2.12.4-1)
bullseye: resolved (fixed in 2.12.4-1)
forky: resolved (fixed in 2.12.4-1)
sid: resolved (fixed in 2.12.4-1)
trixie: resolved (fixed in 2.12.4-1)
OSV
Apache Jackrabbit Authentication Hijacking Vulnerability
osv·2022-05-17
CVE-2016-6801 [HIGH] Apache Jackrabbit Authentication Hijacking Vulnerability
Apache Jackrabbit Authentication Hijacking Vulnerability
Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows remote attackers to hijack the authentication of unspecified victims for requests that create a resource via an HTTP POST request with a (1) missing or (2) crafted Content-Type header.
GHSA
Apache Jackrabbit Authentication Hijacking Vulnerability
ghsa·2022-05-17
CVE-2016-6801 [HIGH] CWE-352 Apache Jackrabbit Authentication Hijacking Vulnerability
Apache Jackrabbit Authentication Hijacking Vulnerability
Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows remote attackers to hijack the authentication of unspecified victims for requests that create a resource via an HTTP POST request with a (1) missing or (2) crafted Content-Type header.
OSV
CVE-2016-6801: Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2
osv·2016-09-21·CVSS 8.8
CVE-2016-6801 [HIGH] CVE-2016-6801: Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2
Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows remote attackers to hijack the authentication of unspecified victims for requests that create a resource via an HTTP POST request with a (1) missing or (2) crafted Content-Type header.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.debian.org/security/2016/dsa-3679http://www.openwall.com/lists/oss-security/2016/09/14/6http://www.securityfocus.com/bid/92966https://issues.apache.org/jira/browse/JCR-4009http://www.debian.org/security/2016/dsa-3679http://www.openwall.com/lists/oss-security/2016/09/14/6http://www.securityfocus.com/bid/92966https://issues.apache.org/jira/browse/JCR-4009
2016-09-21
Published