•  
      request #42231 Missing CSRF protection on tracker hierarchy administration
    Infos
    #42231
    Joris MASSON (jmasson)
    2025-03-31 10:16
    2025-03-17 19:13
    43907
    Details
    Missing CSRF protection on tracker hierarchy administration

    In the administration of a Tracker, in the "Tracker hierarchy", there is no CSRF protection when choosing the list of children trackers.

    Impact

    An attacker could use this vulnerability to trick victims into changing the hierarchy of a tracker.

    CVSSv3.1 score: 4.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L)

    References

    CWE 352
    Cross-Site Request Forgery - OWASP
    CVE-2025-29929

    Trackers
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Joris MASSON (jmasson)
    Closed
    2025-03-18
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-03-27 17:38

    CVE-2025-29929 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Joris MASSON (jmasson)2025-03-17 19:14
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes