CVE-2016-6801

Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows remote attackers to hijack the authentication of unspecified victims for requests that create a resource via an HTTP POST request with a (1) missing or (2) crafted Content-Type header.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:jackrabbit:2.13.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.12.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.10.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.8.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.6.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.6.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.13.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.4.5:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.4.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.4.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.4.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.13.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.12.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.6.5:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.8.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.12.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.6.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.6.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.6.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.10.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.8.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.10.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.10.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.12.1:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Information

Published : 2016-09-21 07:25

Updated : 2016-10-04 10:36


NVD link : CVE-2016-6801

Mitre link : CVE-2016-6801


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

debian

  • debian_linux

apache

  • jackrabbit