Carbon Black CVE-2014-1615 Cross Site Request Forgery Vulnerability
BID:66799
Info
Carbon Black CVE-2014-1615 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 66799 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-1615 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 01 2014 12:00AM |
| Updated: | Mar 19 2015 08:19AM |
| Credit: | Dana James Traversie of Dell SecureWorks |
| Vulnerable: |
Carbonblack Carbon Black 4.1.0.BETA2 Carbonblack Carbon Black 4.1.0.BETA1 Carbonblack Carbon Black 4.0.3 |
| Not Vulnerable: |
Carbonblack Carbon Black 4.1.0 |
Discussion
Carbon Black CVE-2014-1615 Cross Site Request Forgery Vulnerability
Carbon Black is prone to a cross-site request-forgery vulnerabilities because it fails to properly validate HTTP requests.
An attacker can exploit this issue to perform unauthorized actions in the context of a logged-in user of the affected application. This may aid in other attacks.
Carbon Black 4.0.3, 4.1.0.BETA1, and 4.1.0.BETA2 are vulnerable; other versions may also be affected.
Carbon Black is prone to a cross-site request-forgery vulnerabilities because it fails to properly validate HTTP requests.
An attacker can exploit this issue to perform unauthorized actions in the context of a logged-in user of the affected application. This may aid in other attacks.
Carbon Black 4.0.3, 4.1.0.BETA1, and 4.1.0.BETA2 are vulnerable; other versions may also be affected.
Exploit / POC
Carbon Black CVE-2014-1615 Cross Site Request Forgery Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
Solution / Fix
Carbon Black CVE-2014-1615 Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.