CVE-2021-26296
Published: Feb 19, 2021
Modified: Feb 13, 2025
Description
In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache MyFaces Core | affected Apache MyFaces Core 2.2 - < 2.2.14affected Apache MyFaces Core 2.3 - < 2.3.8affected Apache MyFaces Core 2.3-next - < 2.3-next-M5affected Apache MyFaces Core 3.0 - < 3.0.0 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now