Lucene search

K
osvGoogleOSV:GHSA-7QP2-RGXR-29Q4
HistoryMay 24, 2022 - 5:46 p.m.

Missing permission checks in Micro Focus Application Automation Tools Plugin

2022-05-2417:46:58
Google
osv.dev
12
micro focus
application automation
tools plugin
permission checks
vulnerability
csrf

EPSS

0.001

Percentile

22.7%

Micro Focus Application Automation Tools Plugin 6.7 and earlier does not perform permission checks in methods implementing form validation.

This allows attackers with Overall/Read permission to connect to attacker-specified URLs using attacker-specified username and password.

Additionally, these form validation methods do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.

Micro Focus Application Automation Tools Plugin 6.8 requires POST requests and Overall/Administer permission for the affected form validation methods.

EPSS

0.001

Percentile

22.7%

Related for OSV:GHSA-7QP2-RGXR-29Q4