{"api_version":"1","generated_at":"2026-05-16T23:19:24+00:00","cve":"CVE-2018-12413","urls":{"html":"https://cve.report/CVE-2018-12413","api":"https://cve.report/api/cve/CVE-2018-12413.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-12413","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-12413"},"summary":{"title":"CVE-2018-12413","description":"The Schema repository server (tibschemad) component of TIBCO Software Inc.'s TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition, and TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc. TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition: 1.0.0, and TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition: 1.0.0.","state":"PUBLIC","assigner":"security@tibco.com","published_at":"2018-11-06 23:29:00","updated_at":"2019-10-09 23:33:00"},"problem_types":["CWE-352"],"metrics":[],"references":[{"url":"http://www.tibco.com/services/support/advisories","name":"http://www.tibco.com/services/support/advisories","refsource":"MISC","tags":["Vendor Advisory"],"title":"Advisory | TIBCO Software","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/105874","name":"105874","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Multiple TIBCO Products CVE-2018-12413 Cross Site Request Forgery Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.tibco.com/support/advisories/2018/11/tibco-security-advisory-november-6-2018-tibco-messaging-apache-kafka-distribution-schema-repository","name":"https://www.tibco.com/support/advisories/2018/11/tibco-security-advisory-november-6-2018-tibco-messaging-apache-kafka-distribution-schema-repository","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"TIBCO Security Advisory: November 6, 2018 - TIBCO Messaging - Apache Kafka Distribution - Schema Repository | TIBCO Software","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-12413","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-12413","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"12413","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tibco","cpe5":"messaging_-_apache_kafka_distribution_-_schema_repository","cpe6":"1.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"12413","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tibco","cpe5":"messaging_-_apache_kafka_distribution_-_schema_repository","cpe6":"1.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"12413","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tibco","cpe5":"messaging_-_apache_kafka_distribution_-_schema_repository","cpe6":"1.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"12413","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tibco","cpe5":"messaging_-_apache_kafka_distribution_-_schema_repository","cpe6":"1.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@tibco.com","DATE_PUBLIC":"2018-11-06T17:00:00.000Z","ID":"CVE-2018-12413","STATE":"PUBLIC","TITLE":"TIBCO Messaging - Apache Kafka Distribution - Schema Repository Vulnerable to CSRF Attacks"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition","version":{"version_data":[{"affected":"=","version_value":"1.0.0"}]}},{"product_name":"TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition","version":{"version_data":[{"affected":"=","version_value":"1.0.0"}]}}]},"vendor_name":"TIBCO Software Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Schema repository server (tibschemad) component of TIBCO Software Inc.'s TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition, and TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc. TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition: 1.0.0, and TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition: 1.0.0."}]},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.0"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"The impact of this vulnerability includes the theoretical possibility that an attacker could gain full access to the configuration of message schemas used with an Apache Kafka deployment. With such access, the attacker could also configure Apache Kafka communications to fail."}]}]},"references":{"reference_data":[{"name":"http://www.tibco.com/services/support/advisories","refsource":"MISC","url":"http://www.tibco.com/services/support/advisories"},{"name":"105874","refsource":"BID","url":"http://www.securityfocus.com/bid/105874"},{"name":"https://www.tibco.com/support/advisories/2018/11/tibco-security-advisory-november-6-2018-tibco-messaging-apache-kafka-distribution-schema-repository","refsource":"CONFIRM","url":"https://www.tibco.com/support/advisories/2018/11/tibco-security-advisory-november-6-2018-tibco-messaging-apache-kafka-distribution-schema-repository"}]},"solution":[{"lang":"eng","value":"TIBCO has released updated versions of the affected components which address these issues. For each affected system, update to the corresponding software versions:\n\nTIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition version 1.0.0 update to version 1.0.1 or higher\nTIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition version 1.0.0 update to version 1.0.1 or higher.\n"}],"source":{"discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2018-11-06 23:29:00","lastModifiedDate":"2019-10-09 23:33:00","problem_types":["CWE-352"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:tibco:messaging_-_apache_kafka_distribution_-_schema_repository:1.0.0:*:*:*:enterprise:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:tibco:messaging_-_apache_kafka_distribution_-_schema_repository:1.0.0:*:*:*:community:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"12413","Ordinal":"128931","Title":"CVE-2018-12413","CVE":"CVE-2018-12413","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"12413","Ordinal":"1","NoteData":"The Schema repository server (tibschemad) component of TIBCO Software Inc.'s TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition, and TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc. TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition: 1.0.0, and TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition: 1.0.0.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"12413","Ordinal":"2","NoteData":"2018-11-06","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"12413","Ordinal":"3","NoteData":"2018-11-12","Type":"Other","Title":"Modified"}]}}}