CVE-2018-12540
vertx-web: Incomplete CSRF validation by CSRFHandler
Severity Score
8.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
3
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet.
Desde la versión 3.0.0 hasta la 3.5.2 de Eclipse Vert.x, CSRFHandler no aseveró que la cookie XSRF coincidía con la cabecera XSRF/ parámetro form. Esto permite ataques de reproducción con tokens previamente subidos que aún no han caducado.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2018-06-18 CVE Reserved
- 2018-07-12 CVE Published
- 2018-11-19 First Exploit
- 2023-07-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (9)
URL | Date | SRC |
---|---|---|
https://github.com/tafamace/CVE-2018-12540 | 2018-11-19 | |
https://access.redhat.com/errata/RHSA-2018:2371 | 2024-08-05 | |
https://bugs.eclipse.org/bugs/show_bug.cgi?id=536948 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2018-12540 | 2018-08-09 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1600666 | 2018-08-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eclipse Search vendor "Eclipse" | Vert.x Search vendor "Eclipse" for product "Vert.x" | >= 3.0.0 <= 3.5.2 Search vendor "Eclipse" for product "Vert.x" and version " >= 3.0.0 <= 3.5.2" | - |
Affected
|