Vulnerability Description
perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted input into the Search function.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Perfsonar | Perfsonar | >= 4.0, <= 4.4.5 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/170070/perfSONAR-4.4.5-Cross-Site-Request-FThird Party Advisory
- http://packetstormsecurity.com/files/171629/perfSONAR-4.4.5-Cross-Site-Request-F
- https://github.com/renmizo/CVE-2022-41413Third Party Advisory
- http://packetstormsecurity.com/files/170070/perfSONAR-4.4.5-Cross-Site-Request-FThird Party Advisory
- http://packetstormsecurity.com/files/171629/perfSONAR-4.4.5-Cross-Site-Request-F
- https://github.com/renmizo/CVE-2022-41413Third Party Advisory
FAQ
What is CVE-2022-41413?
CVE-2022-41413 is a vulnerability with a CVSS score of 4.3 (MEDIUM). perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted input into the Search function.
How severe is CVE-2022-41413?
CVE-2022-41413 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-41413?
Check the references section above for vendor advisories and patch information. Affected products include: Perfsonar Perfsonar.