René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

151 lines
4.9 KiB
JSON

{
"id": "CVE-2009-1339",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-04-30T20:30:00.420",
"lastModified": "2017-08-17T01:30:17.803",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that update pages, as demonstrated by a URL for a save script in the SRC attribute of an IMG element, a related issue to CVE-2009-1434."
},
{
"lang": "es",
"value": "Vulnerabilidad de falsificaci\u00f3n de petici\u00f3n en sitios cruzados (CSRF) en TWiki anterior a v4.3.1 permite a usuarios remotos autenticados secuestrar la autenticaci\u00f3n de usuarios a su elecci\u00f3n para las peticiones que actualizan p\u00e1ginas, como se demostr\u00f3 por una URL para un script de guardado en el atributo SRC de un elemento IMG, una cuesti\u00f3n relacionada con CVE-2009-1434."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 6.8,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:twiki:twiki:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.3.0",
"matchCriteriaId": "1E38FC46-7F35-4777-87D8-124838860474"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:twiki:twiki:4.1.2:*:*:*:*:*:*:*",
"matchCriteriaId": "9FE3EEC6-7E05-4A37-97AA-D73E7D7A0E01"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:twiki:twiki:4.2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "855671F5-C215-4382-B512-4ABD9D66F13D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:twiki:twiki:4.2.1:*:*:*:*:*:*:*",
"matchCriteriaId": "E9C00515-CFEE-427A-BACE-B3140B0D6C67"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:twiki:twiki:4.2.2:*:*:*:*:*:*:*",
"matchCriteriaId": "E9CF4F9B-7ADF-47A2-A556-10CCF7401DA9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:twiki:twiki:4.2.3:*:*:*:*:*:*:*",
"matchCriteriaId": "81DDB420-E707-4319-8395-531FC0D84E5B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:twiki:twiki:4.2.4:*:*:*:*:*:*:*",
"matchCriteriaId": "0D7A5A57-AE7D-4D3E-A280-41676F355AEE"
}
]
}
]
}
],
"references": [
{
"url": "http://bugs.debian.org/526258",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1022146",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://sourceforge.net/mailarchive/forum.php?thread_name=7E0723DC-CBFF-4DBD-B26C-8686287FF689%40twiki.net&forum_name=twiki-announce",
"source": "cve@mitre.org"
},
{
"url": "http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2009-1339",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://twiki.org/p/pub/Codev/SecurityAlert-CVE-2009-1339/TWiki-4.3.0-c-diff-cve-2009-1339.txt",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "http://www.nabble.com/Bug-526258:-CVE-2009-1339:-CSRF-Vulnerability-with-Image-Tag-td23311575.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2009/1217",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/50254",
"source": "cve@mitre.org"
},
{
"url": "https://launchpad.net/bugs/cve/2009-1339",
"source": "cve@mitre.org"
}
]
}