•  
      request #11217 Account takeover due to a missing CSRF protection on email address change functionnality
    Infos
    #11217
    Thomas Gerbet (tgerbet)
    2018-03-05 18:13
    2018-03-01 11:20
    11550
    Details
    Account takeover due to a missing CSRF protection on email address change functionnality

    Tuleap does not properly check the CSRF challenge when the form allowing a user to change his email is submitted.

    Impact

    An attacker could use this vulnerability to successfully take over a victim's account. Tuleap instances relying on LDAP authentication without the "LDAP write" feature are not impacted by the issue as the email change is not managed by Tuleap.
    CVSSv3 score: 8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

    Credits

    This vulnerability has been found and reported by @mustafaran on the Eclipse Fundation bug tracker.

    References

    CVE-2018-7634

    bugs.eclipse.org: Bug 531434: CSRF vulnerability in tuleap.eclipse.org that can be used to takeover accounts

    CWE-352
    Cross-Site Request Forgery - OWASP

    Other
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    mustafa iran (monochrome)
    Stage
    Empty
    Closed
    2018-03-01
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2018-03-02 11:27
    Mention in the impact that instances relying on the LDAP authentication method are not impacted.

    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2018-03-02 11:23
    Add CVE ID.

    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    • CC list set to mustafa iran (monochrome)
    User avatar
    Thomas Gerbet (tgerbet)2018-03-01 14:56
    Add credits and disclosure date.

    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes