samba: cross-site request forgery vulnerability in SWAT
Published Feb 2, 2013
5.1
MEDIUMCVSS 2.0
EPSS 1.91%
Description
Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.
Affected products
No data.
Configuration 1
- 3.6.0
- 3.6.1
- 3.6.2
- 3.6.3
- 3.6.4
- 3.6.5
- 3.6.6
- 3.6.7
- 3.6.8
- 3.6.9
- 3.6.10
- 3.6.11
Configuration 3
- 3.0.0
- 3.0.1
- 3.0.2
- 3.0.2
- 3.0.2a
- 3.0.3
- 3.0.4
- 3.0.4
- 3.0.5
- 3.0.6
- 3.0.7
- 3.0.8
- 3.0.9
- 3.0.10
- 3.0.11
- 3.0.12
- 3.0.13
- 3.0.14
- 3.0.14
- 3.0.14a
- 3.0.15
- 3.0.16
- 3.0.17
- 3.0.18
- 3.0.19
- 3.0.20
- 3.0.20
- 3.0.20
- 3.0.20a
- 3.0.20b
- 3.0.21
- 3.0.21
- 3.0.21
- 3.0.21
- 3.0.21a
- 3.0.21b
- 3.0.21c
- 3.0.22
- 3.0.23
- 3.0.23
- 3.0.23
- 3.0.23
- 3.0.23
- 3.0.23a
- 3.0.23b
- 3.0.23c
- 3.0.23d
- 3.0.24
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25
- 3.0.25a
- 3.0.25b
- 3.0.25c
- 3.0.26
- 3.0.26
- 3.0.26a
- 3.0.27
- 3.0.27
- 3.0.28
- 3.0.28
- 3.0.29
- 3.0.30
- 3.0.31
- 3.0.32
- 3.0.33
- 3.0.34
- 3.0.35
- 3.0.36
- 3.0.37
- 3.1.0
- 3.2.0
- 3.2.1
- 3.2.2
- 3.2.3
- 3.2.4
- 3.2.5
- 3.2.6
- 3.2.7
- 3.2.8
- 3.2.9
- 3.2.10
- 3.2.11
- 3.2.12
- 3.2.13
- 3.2.14
- 3.2.15
- 3.3.0
- 3.3.1
- 3.3.2
- 3.3.3
- 3.3.4
- 3.3.5
- 3.3.6
- 3.3.7
- 3.3.8
- 3.3.9
- 3.3.10
- 3.3.11
- 3.3.12
- 3.3.13
- 3.3.14
- 3.3.15
- 3.3.16
- 3.4.0
- 3.4.1
- 3.4.2
- 3.4.3
- 3.4.4
- 3.4.5
- 3.4.6
- 3.4.7
- 3.4.8
- 3.4.9
- 3.4.10
- 3.4.11
- 3.4.12
- 3.4.13
- 3.4.14
- 3.4.15
- 3.4.16
- 3.4.17
- 3.5.0
- 3.5.1
- 3.5.2
- 3.5.3
- 3.5.4
- 3.5.5
- 3.5.6
- 3.5.7
- 3.5.8
- 3.5.9
- 3.5.10
- 3.5.11
- 3.5.12
- 3.5.13
- 3.5.14
- 3.5.15
- 3.5.16
- 3.5.17
- 3.5.18
- 3.5.19
- 3.5.20
No data.
Red Hat Enterprise Linux 5
samba-0:3.0.33-3.40.el5_10
Fixed · RHSA-2014:0305
Red Hat Enterprise Linux 5
samba3x-0:3.6.6-0.136.el5
Fixed · RHSA-2013:1310
Red Hat Enterprise Linux 6
samba-0:3.6.9-164.el6
Fixed · RHSA-2013:1542
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | samba-0:3.0.33-3.40.el5_10 | Fixed | RHSA-2014:0305 |
| Red Hat Enterprise Linux 5 | samba3x-0:3.6.6-0.136.el5 | Fixed | RHSA-2013:1310 |
| Red Hat Enterprise Linux 6 | samba-0:3.6.9-164.el6 | Fixed | RHSA-2013:1542 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (18)
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00019.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00042.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00029.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00033.html vendor-advisoryx_refsource_SUSE
- http://osvdb.org/89627 vdb-entryx_refsource_OSVDB
- http://rhn.redhat.com/errata/RHSA-2013-1310.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2013-1542.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2014-0305.html vendor-advisoryx_refsource_REDHAT
- http://www.debian.org/security/2013/dsa-2617 vendor-advisoryx_refsource_DEBIAN
- http://www.samba.org/samba/security/CVE-2013-0214 x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/57631 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-2922-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2013-0214 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=905704 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0248 Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05115993 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2013-0214
- https://www.cve.org/CVERecord?id=CVE-2013-0214
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data