PT-2023-16574 · Opennms · Opennms Meridian+1
CVE-2023-0870
·
Publicado
2023-03-22
·
Atualizado
2023-08-16
CVSS v3.1
8.1
Alta
| Vetor | AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenNMS Meridian versions prior to 2023.1.1
OpenNMS Horizon versions prior to 31.0.6
Description
A form can be manipulated with cross-site request forgery in OpenNMS Meridian and Horizon, potentially allowing an attacker to gain access to confidential information and compromise integrity. The software is intended for installation within an organization's private networks and should not be directly accessible from the Internet.
Recommendations
For OpenNMS Meridian versions prior to 2023.1.1, upgrade to Meridian 2023.1.1 or newer.
For OpenNMS Horizon versions prior to 31.0.6, upgrade to Horizon 31.0.6 or newer.
Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Opennms Horizon
Opennms Meridian