•  
      request #45259 Missing CSRF protections in the File Release System
    Infos
    #45259
    Nicolas Terray (nterray)
    2025-11-12 10:13
    2025-11-03 16:01
    46980
    Details
    Missing CSRF protections in the File Release System

    Most actions of the File Release System are not protected against CSRFs.

    Impact

    An attacker could use this vulnerability to trick victims into doing most actions offered by the FRS.
    CVSSv3.1 score: 4.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L)

    References

    CWE 352
    Cross-Site Request Forgery - OWASP
    CVE-2025-64482

    Delivery/File release system
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2025-11-04
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-11-07 08:53

    CVE-2025-64482 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    • Connected artifacts
    User avatar
    Thomas Gerbet (tgerbet)2025-11-04 11:53
    • Summary
      -Missing CSRF protections in FRS 
      +Missing CSRF protections in the File Release System 
    User avatar
    Thomas Gerbet (tgerbet)2025-11-04 11:50

    • Summary
      -Missing CSRF in FRS 
      +Missing CSRF protections in FRS 
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    • Status changed from Verified to Under review
    User avatar
    Thomas Gerbet (tgerbet)2025-11-03 16:16
    • Category set to Delivery/File release system
    • Status changed from New to Verified
    • Assigned to changed from None to Thomas Gerbet (tgerbet)
    • Reported in version set to All