CVE-2013-0214

Samba 3.x < 3.5.21, 3.6.x < 3.6.12, 4.x < 4.0.2 - Cross-Site Request Forgery in SWAT

Title source: llm
STIX 2.1

Description

Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.

References (13)

Core 13
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/89627
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-02/msg00033.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/57631
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-02/msg00029.html
Vendor Advisory x_refsource_confirm
http://www.samba.org/samba/security/CVE-2013-0214
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0305.html
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2922-1
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2013/dsa-2617
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1310.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1542.html

Scores

EPSS 0.0487
EPSS Percentile 89.7%

Details

CWE
CWE-352
Status published
Products (42)
samba/samba 3.6.0
samba/samba 3.6.1
samba/samba 3.6.2
samba/samba 3.6.3
samba/samba 3.6.4
samba/samba 3.6.5
samba/samba 3.6.6
samba/samba 3.6.7
samba/samba 3.6.8
samba/samba 3.6.9
... and 32 more
Published Feb 02, 2013
Tracked Since Feb 18, 2026