« Volver al listado

CVE-2021-26296

Estado: ModificadaAlta (7.5)—

In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-26296",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache MyFaces Core",
          "versions": [
            {
              "status": "affected",
              "version": "Apache MyFaces Core 2.2",
              "lessThan": "2.2.14",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "Apache MyFaces Core 2.3",
              "lessThan": "2.3.8",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "Apache MyFaces Core 2.3-next",
              "lessThan": "2.3-next-M5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "Apache MyFaces Core 3.0",
              "lessThan": "3.0.0",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-02-19T09:15:13.283",
  "references": [
    {
      "url": "http://packetstormsecurity.com/files/161484/Apache-MyFaces-2.x-Cross-Site-Request-Forgery.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2021/Feb/66",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://lists.apache.org/thread.html/r2b73e2356c6155e9ec78fdd8f72a4fac12f3e588014f5f535106ed9b%40%3Cannounce.apache.org%3E",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20210528-0007/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://packetstormsecurity.com/files/161484/Apache-MyFaces-2.x-Cross-Site-Request-Forgery.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2021/Feb/66",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.apache.org/thread.html/r2b73e2356c6155e9ec78fdd8f72a4fac12f3e588014f5f535106ed9b%40%3Cannounce.apache.org%3E",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20210528-0007/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@apache.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application."
    },
    {
      "lang": "es",
      "value": "En la configuración predeterminada, Apache MyFaces Core versiones 2.2.0 hasta 2.2.13, versiones 2.3.0 hasta 2.3.7, versiones 2.3-next-M1 hasta 2.3-next-M4 y 3.0.0-RC1, usan tokens de tipo cross-site request forgery (CSRF) implícitos y explícitos criptográficamente débiles. Debido a esa limitación, es posible (aunque difícil) para un atacante calcular un valor futuro de token CSRF y usar ese valor para engañar al usuario a ejecutar acciones no deseadas en una aplicación"
    }
  ],
  "lastModified": "2026-06-17T03:43:04.383",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:myfaces:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43C2311F-12BF-4C37-8FF2-B5F555888D92",
              "versionEndIncluding": "2.2.13",
              "versionStartIncluding": "2.2.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:myfaces:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ACA9DF3E-01A7-49C4-9E63-1CA07DA1A2C2",
              "versionEndIncluding": "2.3.7",
              "versionStartIncluding": "2.3.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:myfaces:2.3:next-m1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EF54DDD0-74AA-494B-9F69-C1BA5A208B1F"
            },
            {
              "criteria": "cpe:2.3:a:apache:myfaces:2.3:next-m2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6DBA33A5-97A2-45D4-AAAC-AD6A05888656"
            },
            {
              "criteria": "cpe:2.3:a:apache:myfaces:2.3:next-m3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBE81BF3-66DB-4BD7-A767-547A727CF9B3"
            },
            {
              "criteria": "cpe:2.3:a:apache:myfaces:2.3:next-m4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A377CFB-B073-4B74-9CE9-0D09A08FCFCF"
            },
            {
              "criteria": "cpe:2.3:a:apache:myfaces:3.0.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7CD2AAA3-C1C0-43B2-BD90-742B0B85CD65"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1BE6C1F-2565-4E97-92AA-16563E5660A5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}