// For flags

CVE-2020-14319

amq-on: CSRF (in graphQL requests)

Severity Score

5.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

It was found that the AMQ Online console is vulnerable to a Cross-Site Request Forgery (CSRF) which is exploitable in cases where preflight checks are not instigated or bypassed. For example authorised users using an older browser with Adobe Flash are vulnerable when targeted by an attacker. This flaw affects all versions of AMQ-Online prior to 1.5.2 and Enmasse versions 0.31.0-rc1 up until but not including 0.32.2.

Se encontró que la consola AMQ Online es susceptible a una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) que es explotable en casos donde la comprobaciones preflight que no son instigadas ni omitidas. Por ejemplo, los usuarios autorizados que usan un navegador antiguo con Adobe Flash son vulnerables cuando son apuntados por un atacante. Este fallo afecta a todas las versiones de AMQ-Online anteriores a 1.5.2 y Enmasse versiones 0.31.0-rc1 hasta pero sin incluir la versión 0.32.2

A flaw was found in the AMQ Online console, where it is vulnerable to a Cross-Site Request Forgery attack (CSRF), which is exploitable in cases where preflight checks are not instigated or bypassed. This flaw allows an attacker to target authorized users using an older browser with Adobe Flash. The highest threat from this vulnerability is to integrity and system availability.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
High
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-06-17 CVE Reserved
  • 2020-07-29 CVE Published
  • 2023-03-10 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Redhat
Search vendor "Redhat"
Amq Online
Search vendor "Redhat" for product "Amq Online"
< 1.5.2
Search vendor "Redhat" for product "Amq Online" and version " < 1.5.2"
-
Affected
Redhat
Search vendor "Redhat"
Enmasse
Search vendor "Redhat" for product "Enmasse"
< 0.32.2
Search vendor "Redhat" for product "Enmasse" and version " < 0.32.2"
-
Affected