Description
Important: Bypass of CSRF prevention filter CVE-2012-4431
The CSRF prevention filter could be bypassed if a request was made to a protected resource without a session identifier present in the request.
Affected Apache Tomcat versions (7.0.0 - 7.0.31).
Remediation
Upgrade to the latest version of Apache Tomcat.
References
Related Vulnerabilities
osCommerce Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-18573)
Oracle Database Server CVE-2014-6563 Vulnerability (CVE-2014-6563)
WordPress Plugin Shantz WordPress QOTD Cross-Site Request Forgery (1.2.2)
WordPress Plugin Product Reviews Import Export for WooCommerce CSV Injection (1.4.8)