GHSA-678x-xfp4-r92r

    Dashboard / Vulnerabilities / GHSA-678x-xfp4-r92r

    GHSA-678x-xfp4-r92r

    Published: 2 May 2022Last Modified: 9 Apr 2025
    Aliases:

    Summary: Apache Geronimo Application Server CSRF vulnerabilities

    Details: Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, (2) upload applications, and perform unspecified other administrative actions, as demonstrated by (3) a Shutdown request to console/portal//Server/Shutdown.

    Affected packages

    Package

    Name: org.apache.geronimo.plugins:console

    Purl: pkg:maven/org.apache.geronimo.plugins/console

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.1.4

    Affected versions

    2.1
    2.1.1
    2.1.2
    2.1.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-678x-xfp4-r92r | CVE-DB