Cross-Site Request Forgery Vulnerability in Apache Jackrabbit
CVE-2016-6801
8.8HIGH
What is CVE-2016-6801?
A CSRF vulnerability exists within the content-type check of Apache Jackrabbit's WebDAV feature. This flaw allows remote attackers to hijack user authentication for specific requests that create resources. Exploitation requires the submission of an HTTP POST request that either lacks a valid Content-Type header or contains a maliciously crafted one, potentially leading to unauthorized actions on behalf of victims.