THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2023-6022

Cross-Site Request Forgery (CSRF) in prefecthq/prefect

Reserved:2023-11-08
Published:2023-11-16
Updated:2024-05-15

Description

Cross-Site Request Forgery (CSRF) in GitHub repository prefecthq/prefect prior to 2.16.5.



HIGH: 8.8CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-352 Cross-Site Request Forgery (CSRF)

Product status

Any version before 2.16.5
affected

References

https://huntr.com/bounties/dab47d99-551c-4355-9ab1-c99cb90235af

https://github.com/prefecthq/prefect/commit/227dfcc7e3374c212a4bcd68b14e090b1c02d9d3

cve.org CVE-2023-6022

nvd.nist.gov CVE-2023-6022

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2023-6022