A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the Access-Control-Allow-Origin HTTP access control flag). This can lead to unauthorized information leak if a user with admin privileges visits a specially-crafted web page provided by a remote attacker.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jboss_application_server | Redhat | 7.0.0 (including) | 7.0.0 (including) |
Jboss_application_server | Redhat | 7.0.0-alpha1 (including) | 7.0.0-alpha1 (including) |
Jboss_application_server | Redhat | 7.0.0-beta1 (including) | 7.0.0-beta1 (including) |
Jboss_application_server | Redhat | 7.0.0-beta2 (including) | 7.0.0-beta2 (including) |
Jboss_application_server | Redhat | 7.0.0-beta3 (including) | 7.0.0-beta3 (including) |
Jboss_application_server | Redhat | 7.0.0-cr1 (including) | 7.0.0-cr1 (including) |
Jboss_application_server | Redhat | 7.0.1 (including) | 7.0.1 (including) |
Jboss_application_server | Redhat | 7.0.2 (including) | 7.0.2 (including) |