|
|
| |
|
| |
couchdb: cross-site request forgery
| Package(s): | couchdb |
CVE #(s): | CVE-2010-2234
|
| Created: | September 21, 2010 |
Updated: | September 22, 2010 |
| Description: |
From the Red Hat bugzilla:
Apache CouchDB prior to 0.11.2 and 1.0.1 are vulnerable to cross site request forgery (CSRF) attacks. A malicious web site can POST arbitrary JavaScript code to wellknown CouchDB installation URLs and make the browser execute the injected JavaScript in the security context of CouchDB's admin interface Futon.
|
| Alerts: |
|
( Log in to post comments)
|
|
|