-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from improper CSRF validation logic in the isValidRequest method. The commit diffs show critical fixes to Content-Type header parsing (including case normalization and parameter stripping), Referer host validation, and error logging. Pre-patch versions allowed requests with missing/malformed Content-Type headers and insufficient Referer checks, enabling CSRF attacks. The function's direct involvement in request validation and the nature of the fixes confirm its role in the vulnerability.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.jackrabbit:jackrabbit-webdav | maven | >= 2.4.0, < 2.4.6 | 2.4.6 |
| org.apache.jackrabbit:jackrabbit-webdav | maven | >= 2.6.0, < 2.6.6 | 2.6.6 |
| org.apache.jackrabbit:jackrabbit-webdav |
| maven |
| >= 2.8.0, < 2.8.3 |
| 2.8.3 |
| org.apache.jackrabbit:jackrabbit-webdav | maven | >= 2.10.0, < 2.10.4 | 2.10.4 |
| org.apache.jackrabbit:jackrabbit-webdav | maven | >= 2.12.0, < 2.12.4 | 2.12.4 |
| org.apache.jackrabbit:jackrabbit-webdav | maven | >= 2.13.0, < 2.13.3 | 2.13.3 |
Ongoing coverage of React2Shell