CVE-2020-36623

A vulnerability was found in Pengu. It has been declared as problematic. Affected by this vulnerability is the function runApp of the file src/index.js. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The name of the patch is aea66f12b8cdfc3c8c50ad6a9c89d8307e9d0a91. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216475.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:pengu_project:pengu:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:29

Type Values Removed Values Added
References () https://github.com/jtojnar/pengu/commit/aea66f12b8cdfc3c8c50ad6a9c89d8307e9d0a91 - Patch, Third Party Advisory () https://github.com/jtojnar/pengu/commit/aea66f12b8cdfc3c8c50ad6a9c89d8307e9d0a91 - Patch, Third Party Advisory
References () https://vuldb.com/?id.216475 - Third Party Advisory, VDB Entry () https://vuldb.com/?id.216475 - Third Party Advisory, VDB Entry
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 4.3
Summary
  • (es) Se encontró una vulnerabilidad en Pengu. Ha sido declarada problemática. La función runApp del archivo src/index.js es afectada por esta vulnerabilidad. La manipulación conduce a la Cross-Site Request Forgery (CSRF). El ataque se puede lanzar de forma remota. El nombre del parche es aea66f12b8cdfc3c8c50ad6a9c89d8307e9d0a91. Se recomienda aplicar un parche para solucionar este problema. El identificador asociado de esta vulnerabilidad es VDB-216475.

Information

Published : 2022-12-21 19:15

Updated : 2024-11-21 05:29


NVD link : CVE-2020-36623

Mitre link : CVE-2020-36623

CVE.ORG link : CVE-2020-36623


JSON object : View

Products Affected

pengu_project

  • pengu
CWE
CWE-863

Incorrect Authorization

CWE-352

Cross-Site Request Forgery (CSRF)