CVE Database
/

CVE-2021-26296

Back to search

CVE-2021-26296

Published: Feb 19, 2021

Modified: Feb 13, 2025

PUBLISHED

Description

In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.

VendorProductVersions

Apache Software Foundation

Apache MyFaces Core

affected
Apache MyFaces Core 2.2 - < 2.2.14
affected
Apache MyFaces Core 2.3 - < 2.3.8
affected
Apache MyFaces Core 2.3-next - < 2.3-next-M5
affected
Apache MyFaces Core 3.0 - < 3.0.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now