[CVE-2019-0235 ] Apache OFBiz multiple CSRF vulnerabilities

2020-04-30 Thread jler...@apache.org

Severity:
Important

Vendor:
The Apache Software Foundation

Versions Affected:
OFBiz 17.12.01

Description:
Apache OFBiz is vulnerable to CSRF attacks

Mitigation:
Upgrade to 17.12.03 or manually apply the commits at OFBIZ-11470


Credit:
Initially known by the OFBiz security team (OFBIZ-10427),
also reported later by
Man Yue Mo via RT 
Shuibo Ye 
Vikash Patnaik 
Sonali Agrahari 
Girish Vasmatkar 
Dinesh Kumar Mohanty 
Jason Nordenstam 
Pradeep Jairamani 
Faiz Zaidi 

References:
https://ofbiz.apache.org/security.html



[CVE-2019-0235 ] Apache OFBiz multiple CSRF vulnerabilities

2020-04-30 Thread jler...@apache.org

Severity:
Important

Vendor:
The Apache Software Foundation

Versions Affected:
OFBiz 17.12.01

Description:
Apache OFBiz is vulnerable to CSRF attacks

Mitigation:
Upgrade to 17.12.03 or manually apply the commits at OFBIZ-11470


Credit:
Initially known by the OFBiz security team (OFBIZ-10427),
also reported later by
Man Yue Mo via RT 
Shuibo Ye 
Vikash Patnaik 
Sonali Agrahari 
Girish Vasmatkar 
Dinesh Kumar Mohanty 
Jason Nordenstam 
Pradeep Jairamani 
Faiz Zaidi 

References:
https://ofbiz.apache.org/security.html