A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to unauthorized information leak if a user with admin privileges visits a specially-crafted web page provided by a remote attacker.
2019-11-26T03:15:10.787
2024-11-21T01:30:50.653
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:N/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | jboss_application_server | 7.0.0 | Yes |
Application | redhat | jboss_application_server | 7.0.0 | Yes |
Application | redhat | jboss_application_server | 7.0.0 | Yes |
Application | redhat | jboss_application_server | 7.0.0 | Yes |
Application | redhat | jboss_application_server | 7.0.0 | Yes |
Application | redhat | jboss_application_server | 7.0.0 | Yes |
Application | redhat | jboss_application_server | 7.0.1 | Yes |
Application | redhat | jboss_application_server | 7.0.2 | Yes |