Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later.
Workaround:
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://lists.apache.org/thread/txrgykjkpt80t57kzpbjo8kfrv8ss02c | mailing list vendor advisory mitigation |
http://www.openwall.com/lists/oss-security/2022/02/25/1 | mailing list third party advisory mitigation |