CVE-2014-9385

Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger arbitrary code execution via a ZenPack upload, aka ZEN-15388.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zenoss:zenoss_core:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:2.4.5:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:2.5.2:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:4.2.3:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:4.2.4:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:4.2.5:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:5.0.0:beta_1:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:5.0.0:beta_2:*:*:*:*:*:*
cpe:2.3:a:zenoss:zenoss_core:5.0.0:beta_3:*:*:*:*:*:*

History

No history.

Information

Published : 2014-12-15 18:59

Updated : 2023-12-10 11:31


NVD link : CVE-2014-9385

Mitre link : CVE-2014-9385

CVE.ORG link : CVE-2014-9385


JSON object : View

Products Affected

zenoss

  • zenoss_core
CWE
CWE-352

Cross-Site Request Forgery (CSRF)