Vulnerability Description
JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approach.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jasperforge | Jasperreports Server Community Project | 3.7.0 |
Related Weaknesses (CWE)
References
- http://www.csirtcv.gva.es/es/alertas/vulnerabilidad-en-jasperserver.html
- http://www.csirtcv.gva.es/sites/all/files/images/content/%5BCSIRT-cv%5D%20Jasper
- http://www.kb.cert.org/vuls/id/519588US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-8ELLJCUS Government Resource
- http://www.securityfocus.com/bid/49649
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69849
- http://www.csirtcv.gva.es/es/alertas/vulnerabilidad-en-jasperserver.html
- http://www.csirtcv.gva.es/sites/all/files/images/content/%5BCSIRT-cv%5D%20Jasper
- http://www.kb.cert.org/vuls/id/519588US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-8ELLJCUS Government Resource
- http://www.securityfocus.com/bid/49649
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69849
FAQ
What is CVE-2011-1911?
CVE-2011-1911 is a vulnerability with a CVSS score of 6.8 (MEDIUM). JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery ...
How severe is CVE-2011-1911?
CVE-2011-1911 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-1911?
Check the references section above for vendor advisories and patch information. Affected products include: Jasperforge Jasperreports Server Community Project.