Form Can Be Manipulated with Cross-Site Request Forgery (CSRF)
CVE-2023-0870
8.1HIGH
What is CVE-2023-0870?
A cross-site request forgery vulnerability exists in various versions of OpenNMS Meridian and Horizon, potentially enabling attackers to manipulate forms and gain access to sensitive information. This vulnerability compromises the integrity of the application. To mitigate this risk, users are advised to upgrade to Meridian version 2023.1.1 or Horizon version 31.0.6 or later. OpenNMS is intended for installation in private networks and should not be accessible directly from the Internet, further highlighting the importance of following best practices for network security.
Affected Version(s)
Horizon Windows 31.0.6
Meridian Linux 2020.1.0 < 2020.1.33
Meridian Linux 2021.1.0 < 2021.1.25