cbcvebase.
CVE-2021-26296
published 2021-02-19

CVE-2021-26296: In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically…

PriorityP342high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
3.03%
85.9th percentile
In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.

Affected

8 ranges
VendorProductVersion rangeFixed in
apachemyfaces
apachemyfaces
apachemyfaces2.2.0 – 2.2.13
apachemyfaces2.3.0 – 2.3.7
apache_software_foundationapache_myfaces_core>= Apache MyFaces Core 2.2 < 2.2.142.2.14
apache_software_foundationapache_myfaces_core>= Apache MyFaces Core 2.3 < 2.3.82.3.8
apache_software_foundationapache_myfaces_core>= Apache MyFaces Core 2.3-next < 2.3-next-M52.3-next-M5
apache_software_foundationapache_myfaces_core>= Apache MyFaces Core 3.0 < 3.0.03.0.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.