Back

MEDIUM

samba: cross-site request forgery vulnerability in SWAT

Published Feb 2, 2013

Description

Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (18)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Feb 2, 2013
Updated Aug 6, 2024
Reserved Dec 6, 2012

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 16, 2026

Red Hat

Severity Moderate
Public date Jan 30, 2013
Bugzilla 905704

ENISA EUVD

Assigner redhat
Published Feb 2, 2013
Updated Aug 6, 2024

GitHub

No data