Headline
GHSA-cw2v-wv4g-w4p6: rdiffweb CSRF vulnerability in admin area can lead to deletion of repositories and users
rdiffweb prior to 2.4.5 is vulnerable to Cross-Site Request Forgery (CSRF). An attacker exploiting this vulnerability can use it to delete repositories and users.
- GitHub Advisory Database
- GitHub Reviewed
- CVE-2022-3232
rdiffweb CSRF vulnerability in admin area can lead to deletion of repositories and users
Moderate severity GitHub Reviewed Published Sep 18, 2022 • Updated Sep 20, 2022
Package
pip rdiffweb (pip)
Affected versions
< 2.4.5
Description
Related news
CVE-2022-3232
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.5.