Apache Geronimo Application Server CSRF vulnerabilities
Moderate severity
GitHub Reviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Feb 26, 2024
Package
Affected versions
< 2.1.4
Patched versions
2.1.4
Description
Published by the National Vulnerability Database
Apr 17, 2009
Published to the GitHub Advisory Database
May 2, 2022
Reviewed
Jul 29, 2022
Last updated
Feb 26, 2024
Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, (2) upload applications, and perform unspecified other administrative actions, as demonstrated by (3) a Shutdown request to console/portal//Server/Shutdown.
References