CVE-2016-7034
published 2016-09-07CVE-2016-7034: The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query strings…
PriorityP433high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.13%
62.7th percentile
The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query strings, which makes easier for remote attackers to (1) bypass CSRF protection mechanisms or (2) conduct cross-site request forgery (CSRF) attacks by obtaining an old token.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_bpm_suite | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Dashbuilder: insecure handling of CSRF token
vendor_redhat·2016-09-06·CVSS 8.8
CVE-2016-7034 [HIGH] CWE-352 Dashbuilder: insecure handling of CSRF token
Dashbuilder: insecure handling of CSRF token
The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query strings, which makes easier for remote attackers to (1) bypass CSRF protection mechanisms or (2) conduct cross-site request forgery (CSRF) attacks by obtaining an old token.
It has been reported that CSRF tokens are not properly handled in JBoss BPM suite dashbuilder. Old tokens generated during an active session can be used to bypass CSRF protection. In addition, the tokens are sent in query string so they can be exposed through the browser's history, referrers, web logs, and other sources. Attackers may be able to obtain old tokens from various sources in the network and perform CSRF attacks succ
GHSA
GHSA-29p9-chjc-5c6w: The dashbuilder in Red Hat JBoss BPM Suite 6
ghsa_unreviewed·2022-05-14
CVE-2016-7034 [HIGH] CWE-352 GHSA-29p9-chjc-5c6w: The dashbuilder in Red Hat JBoss BPM Suite 6
The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query strings, which makes easier for remote attackers to (1) bypass CSRF protection mechanisms or (2) conduct cross-site request forgery (CSRF) attacks by obtaining an old token.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2017-0557.htmlhttp://www.securityfocus.com/bid/92760https://access.redhat.com/errata/RHSA-2018:0296https://bugzilla.redhat.com/show_bug.cgi?id=1373347http://rhn.redhat.com/errata/RHSA-2017-0557.htmlhttp://www.securityfocus.com/bid/92760https://access.redhat.com/errata/RHSA-2018:0296https://bugzilla.redhat.com/show_bug.cgi?id=1373347
2016-09-07
Published