Description
Important: Bypass of CSRF prevention filter CVE-2012-4431
The CSRF prevention filter could be bypassed if a request was made to a protected resource without a session identifier present in the request.
Affected Apache Tomcat versions (7.0.0 - 7.0.31).
Remediation
Upgrade to the latest version of Apache Tomcat.
References
Related Vulnerabilities
WordPress Plugin Tickera-WordPress Event Ticketing Cross-Site Request Forgery (3.4.9.9)
WordPress Plugin Uncanny Toolkit for LearnDash Cross-Site Request Forgery (3.6.4.1)
WordPress Plugin Fonts-Google Fonts Typography Cross-Site Scripting (3.0.2)
WordPress Plugin Flamingo Code Injection (1.1)
WordPress Plugin Nextend Facebook Connect Unspecified Vulnerability (1.5.7)