CVE-2023-6022

Cross-Site Request Forgery (CSRF) in GitHub repository prefecthq/prefect prior to 2.16.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:prefect:prefect:-:*:*:*:*:*:*:*

History

15 May 2024, 11:15

Type Values Removed Values Added
References
  • () https://github.com/prefecthq/prefect/commit/227dfcc7e3374c212a4bcd68b14e090b1c02d9d3 -
Summary An attacker is able to steal secrets and potentially gain remote code execution via CSRF using the open source Prefect web server's API. Cross-Site Request Forgery (CSRF) in GitHub repository prefecthq/prefect prior to 2.16.5.

30 Nov 2023, 13:15

Type Values Removed Values Added
CWE CWE-352
Summary An attacker is able to steal secrets and potentially gain remote code execution via CSRF using the Prefect API. An attacker is able to steal secrets and potentially gain remote code execution via CSRF using the open source Prefect web server's API.

24 Nov 2023, 23:05

Type Values Removed Values Added
First Time Prefect prefect
Prefect
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:prefect:prefect:-:*:*:*:*:*:*:*
References () https://huntr.com/bounties/dab47d99-551c-4355-9ab1-c99cb90235af - () https://huntr.com/bounties/dab47d99-551c-4355-9ab1-c99cb90235af - Exploit

16 Nov 2023, 17:30

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-16 17:15

Updated : 2024-05-15 11:15


NVD link : CVE-2023-6022

Mitre link : CVE-2023-6022


JSON object : View

Products Affected

prefect

  • prefect
CWE
CWE-352

Cross-Site Request Forgery (CSRF)