MEDIUM
Cross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authentication of users for unspecified commands via unspecified vectors, as demonstrated by bypassing authentication requirements for CVE-2013-7106
Published Jan 14, 2014
6.8
MEDIUMCVSS 2.0
EPSS 1.01%
Description
Cross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authentication of users for unspecified commands via unspecified vectors, as demonstrated by bypassing authentication requirements for CVE-2013-7106.
Affected products
No data.
OR
- ≤ 1.10.2
- 0.8.0
- 0.8.1
- 0.8.2
- 0.8.3
- 0.8.4
- 1.0
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.2.0
- 1.2.1
- 1.3.0
- 1.3.1
- 1.4.0
- 1.4.1
- 1.6.0
- 1.6.1
- 1.6.2
- 1.7.0
- 1.7.1
- 1.7.2
- 1.7.3
- 1.7.4
- 1.8.0
- 1.8.1
- 1.8.2
- 1.8.3
- 1.8.4
- 1.8.5
- 1.9.0
- 1.9.1
- 1.9.2
- 1.9.3
- 1.9.4
- 1.10.0
- 1.10.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00061.html vendor-advisoryx_refsource_SUSE
- http://www.openwall.com/lists/oss-security/2013/12/16/4 mailing-listx_refsource_MLIST
- https://dev.icinga.org/issues/5250 x_refsource_MISCVendor Advisory
- https://dev.icinga.org/issues/5346 x_refsource_CONFIRMVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-6893 Advisory
- https://www.icinga.org/2013/12/17/icinga-security-releases-1-10-2-1-9-4-1-8-5/ x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-updates/2014-02/msg00061.html | vendor-advisoryx_refsource_SUSE | |
| http://www.openwall.com/lists/oss-security/2013/12/16/4 | mailing-listx_refsource_MLIST | |
| https://dev.icinga.org/issues/5250 | x_refsource_MISCVendor Advisory | |
| https://dev.icinga.org/issues/5346 | x_refsource_CONFIRMVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-6893 | Advisory | |
| https://www.icinga.org/2013/12/17/icinga-security-releases-1-10-2-1-9-4-1-8-5/ | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 14, 2014
Updated Aug 6, 2024
Reserved Dec 15, 2013
Link CVE-2013-7107
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data