CVE-2012-4386

Publication date 5 September 2012

Last updated 24 July 2024


Ubuntu priority

Description

The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session attribute.

Status

Package Ubuntu Release Status
libstruts1.2-java 12.04 LTS precise
Not affected
11.10 oneiric
Not affected
11.04 natty
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy
Not affected


Access our resources on patching vulnerabilities