1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
|
Candidate: CVE-2009-1339
PublicDate: 2009-04-30
References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1339
http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2009-1339
Description:
Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1
allows remote authenticated users to hijack the authentication of arbitrary
users for requests that update pages, as demonstrated by a URL for a save
script in the SRC attribute of an IMG element, a related issue to
CVE-2009-1434.
Ubuntu-Description:
Notes:
Bugs:
https://bugs.edge.launchpad.net/ubuntu/+source/twiki/+bug/383085
Priority: medium
Discovered-by:
Assigned-to:
Patches_twiki:
upstream: http://twiki.org/p/pub/Codev/SecurityAlert-CVE-2009-1339/TWiki-4.3.0-c-diff-cve-2009-1339.txt
upstream_twiki: needs-triage
dapper_twiki: ignored (reached end-of-life)
hardy_twiki: ignored (reached end-of-life)
intrepid_twiki: needs-triage (reached end-of-life)
jaunty_twiki: ignored (reached end-of-life)
karmic_twiki: ignored (reached end-of-life)
lucid_twiki: DNE
maverick_twiki: DNE
natty_twiki: DNE
oneiric_twiki: DNE
devel_twiki: DNE
|