CVE-2011-2522
Summary
| CVE | CVE-2011-2522 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-07-29 20:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons, (2) start daemons, (3) add shares, (4) remove shares, (5) add printers, (6) remove printers, (7) add user accounts, or (8) remove user accounts, as demonstrated by certain start, stop, and restart parameters to the status program. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Samba SWAT Cross Site Request Forgery Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| SecurityTracker: Samba Web Administration Tool (SWAT) Input Validation Flaws Permit Cross-Site Request Forgery and Cross-Site Scripting Attacks | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Third Party Advisory, VDB Entry |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Samba Web Administration Tool Cross-Site Request Forgery +PoC - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | Third Party Advisory |
| Samba - Security Announcement Archive | af854a3a-2127-422b-91ae-364da2661108 | www.samba.org | Vendor Advisory |
| JVN#29529126: Samba Web Administration Tool vulnerable to cross-site request forgery | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | Third Party Advisory |
| Ubuntu update for samba - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| mandriva.com | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| USN-1182-1: Samba vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | Third Party Advisory |
| SWAT Samba Web Administration Tool Cross-Site Request Forgery PoC | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Bug 8290 – CSRF vulnerability in SWAT; CVE-2011-2522 | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.samba.org | Issue Tracking, Patch, Third Party Advisory |
| osvdb.org/74071 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| Samba - Release Notes Archive | af854a3a-2127-422b-91ae-364da2661108 | samba.org | Vendor Advisory |
| Debian -- Security Information -- DSA-2290-1 samba | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| Bug 721348 – CVE-2011-2522 samba (SWAT): Absent CSRF protection in various Samba web configuration formulars | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| '[security bulletin] HPSBUX02768 SSRT100664 rev.1 - CIFS Server (Samba), Remote Cross Site Request Fo' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List, Third Party Advisory |
| Debian update for samba - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| www.itrc.hp.com/service/cki/docDisplay.do | af854a3a-2127-422b-91ae-364da2661108 | www.itrc.hp.com | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.