Crucible: Cross-Site Request Forgery (CSRF)

XMLWordPrintable

    • Type: Public Security Vulnerability
    • Resolution: Fixed
    • Priority: Low
    • 4.8.15
    • Affects Version/s: 4.8.14
    • Component/s: None
    • 6.4
    • Medium
    • CSRF (Cross-Site Request Forgery)

      Given some pre-conditions, it is possible to bypass CSRF protections on all pages. Most significantly, this includes the ability to add new admin users. It’s not “strictly” Cross-Site Request Forgery, since the attack must come from the same site (but different origin), but given the preconditions, it has the same effect.

      An attacker with the pre-conditions below could create a new admin account, thus compromise all data stored on the Fisheye / Crucible server.

              Assignee:
              Unassigned
              Reporter:
              Oleh Shchur (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: