Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows remote attackers to hijack the authentication of unspecified victims for requests that create a resource via an HTTP POST request with a (1) missing or (2) crafted Content-Type header.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2016-09-21T14:00:00

Updated: 2016-09-29T18:57:01

Reserved: 2016-08-12T00:00:00


Link: CVE-2016-6801

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2016-09-21T14:25:21.737

Modified: 2016-10-04T17:36:35.783


Link: CVE-2016-6801

JSON object: View

cve-icon Redhat Information

No data.

CWE