•  
      request #45632 Missing CSRF protections in tracker field dependencies
    Infos
    #45632
    Nicolas Terray (nterray)
    2025-12-08 10:31
    2025-11-21 13:38
    47354
    Details
    Missing CSRF protections in tracker field dependencies

    There is no CSRF protection when manipulating tracker field dependencies.

    Impact

    An attacker could use this vulnerability to trick victims into modifying tracker field dependencies.
    CVSSv3.1 score: 4.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L)

    References

    CWE 352
    Cross-Site Request Forgery - OWASP
    CVE-2025-65962

    Trackers
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Nicolas Terray (nterray)
    Closed
    2025-11-24
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-11-25 08:02

    CVE-2025-65962 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2025-11-24 11:34
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2025-11-24 11:31
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    • Status changed from Reopen to Closed
    • Close date set to 2025-11-24
    User avatar
    Thomas Gerbet (tgerbet)2025-11-24 10:12
    • Summary
      -Missing CSRF in tracker field dependencies 
      +Missing CSRF protections in tracker field dependencies