A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the Access-Control-Allow-Origin HTTP access control flag). This can lead to unauthorized information leak if a user with admin privileges visits a specially-crafted web page provided by a remote attacker.
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jboss_application_server | Redhat | 7.0.0 (including) | 7.0.0 (including) |
Jboss_application_server | Redhat | 7.0.0-alpha1 (including) | 7.0.0-alpha1 (including) |
Jboss_application_server | Redhat | 7.0.0-beta1 (including) | 7.0.0-beta1 (including) |
Jboss_application_server | Redhat | 7.0.0-beta2 (including) | 7.0.0-beta2 (including) |
Jboss_application_server | Redhat | 7.0.0-beta3 (including) | 7.0.0-beta3 (including) |
Jboss_application_server | Redhat | 7.0.0-cr1 (including) | 7.0.0-cr1 (including) |
Jboss_application_server | Redhat | 7.0.1 (including) | 7.0.1 (including) |
Jboss_application_server | Redhat | 7.0.2 (including) | 7.0.2 (including) |