Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-cw2v-wv4g-w4p6: rdiffweb CSRF vulnerability in admin area can lead to deletion of repositories and users

rdiffweb prior to 2.4.5 is vulnerable to Cross-Site Request Forgery (CSRF). An attacker exploiting this vulnerability can use it to delete repositories and users.

ghsa
#csrf#vulnerability#web#git
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2022-3232

rdiffweb CSRF vulnerability in admin area can lead to deletion of repositories and users

Moderate severity GitHub Reviewed Published Sep 18, 2022 • Updated Sep 20, 2022

Package

pip rdiffweb (pip)

Affected versions

< 2.4.5

Description

Related news

CVE-2022-3232

Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.5.