CVE-2021-26296
published 2021-02-19CVE-2021-26296: In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically…
PriorityP342high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
3.03%
85.9th percentile
In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | myfaces | — | — |
| apache | myfaces | — | — |
| apache | myfaces | 2.2.0 – 2.2.13 | — |
| apache | myfaces | 2.3.0 – 2.3.7 | — |
| apache_software_foundation | apache_myfaces_core | >= Apache MyFaces Core 2.2 < 2.2.14 | 2.2.14 |
| apache_software_foundation | apache_myfaces_core | >= Apache MyFaces Core 2.3 < 2.3.8 | 2.3.8 |
| apache_software_foundation | apache_myfaces_core | >= Apache MyFaces Core 2.3-next < 2.3-next-M5 | 2.3-next-M5 |
| apache_software_foundation | apache_myfaces_core | >= Apache MyFaces Core 3.0 < 3.0.0 | 3.0.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Cryptographically weak CSRF tokens in Apache MyFaces
osv·2021-06-16
CVE-2021-26296 [HIGH] Cryptographically weak CSRF tokens in Apache MyFaces
Cryptographically weak CSRF tokens in Apache MyFaces
In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.
Mitigation:
Existing web.xml configuration parameters can be used to direct
MyFaces to use SecureRandom for CSRF token generation:
org.apache.myfaces.RANDOM_KEY_IN_VIEW_STATE_SESSION_TOKEN=secureRandom
org.apache.myfaces.RANDOM_KEY_IN_CSRF_SESSION_TOKEN=secureRandom
org.apache.myfaces.RANDOM_KEY_IN_WEBSOCKET_SESS
GHSA
Cryptographically weak CSRF tokens in Apache MyFaces
ghsa·2021-06-16
CVE-2021-26296 [HIGH] CWE-330 Cryptographically weak CSRF tokens in Apache MyFaces
Cryptographically weak CSRF tokens in Apache MyFaces
In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.
Mitigation:
Existing web.xml configuration parameters can be used to direct
MyFaces to use SecureRandom for CSRF token generation:
org.apache.myfaces.RANDOM_KEY_IN_VIEW_STATE_SESSION_TOKEN=secureRandom
org.apache.myfaces.RANDOM_KEY_IN_CSRF_SESSION_TOKEN=secureRandom
org.apache.myfaces.RANDOM_KEY_IN_WEBSOCKET_SESS
Red Hat
myfaces: Cross-site request forgery vulnerability in Apache MyFaces
vendor_redhat·2021-02-18·CVSS 7.5
CVE-2021-26296 [HIGH] CWE-352 myfaces: Cross-site request forgery vulnerability in Apache MyFaces
myfaces: Cross-site request forgery vulnerability in Apache MyFaces
In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.
Statement: Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it was deprecated as of RHOSP 14 and is only receiving security fixes for Important and Critical flaws.
Package: jsf-impl-myfaces (Red Hat Decision Manager 7) - Will not fix
Package: myfaces-impl (Red Hat
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/161484/Apache-MyFaces-2.x-Cross-Site-Request-Forgery.htmlhttp://seclists.org/fulldisclosure/2021/Feb/66https://lists.apache.org/thread.html/r2b73e2356c6155e9ec78fdd8f72a4fac12f3e588014f5f535106ed9b%40%3Cannounce.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20210528-0007/http://packetstormsecurity.com/files/161484/Apache-MyFaces-2.x-Cross-Site-Request-Forgery.htmlhttp://seclists.org/fulldisclosure/2021/Feb/66https://lists.apache.org/thread.html/r2b73e2356c6155e9ec78fdd8f72a4fac12f3e588014f5f535106ed9b%40%3Cannounce.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20210528-0007/
2021-02-19
Published