Description
Important: Bypass of CSRF prevention filter CVE-2012-4431
The CSRF prevention filter could be bypassed if a request was made to a protected resource without a session identifier present in the request.
Affected Apache Tomcat versions (7.0.0 - 7.0.31).
Remediation
Upgrade to the latest version of Apache Tomcat.
References
Related Vulnerabilities
WordPress Plugin User Login History Multiple Cross-Site Scripting Vulnerabilities (1.5.2)
WordPress Plugin Social Auto Poster-WordPress Scheduler & Marketing Arbitrary File Upload (5.3.14)
WordPress Plugin WP eCommerce Security Bypass (3.8.14.3)
XWiki Improper Preservation of Permissions Vulnerability (CVE-2021-21379)