Apache Tomcat version older than 7.0.32

Description

Important: Bypass of CSRF prevention filter CVE-2012-4431

The CSRF prevention filter could be bypassed if a request was made to a protected resource without a session identifier present in the request.

Affected Apache Tomcat versions (7.0.0 - 7.0.31).

Remediation

Upgrade to the latest version of Apache Tomcat.

References
Severity
Classification
Tags
  • Configuration  Missing Update