Form Can Be Manipulated with Cross-Site Request Forgery (CSRF)
CVE-2023-0870

8.1HIGH

Key Information:

Vendor
CVE Published:
22 March 2023

What is CVE-2023-0870?

A cross-site request forgery vulnerability exists in various versions of OpenNMS Meridian and Horizon, potentially enabling attackers to manipulate forms and gain access to sensitive information. This vulnerability compromises the integrity of the application. To mitigate this risk, users are advised to upgrade to Meridian version 2023.1.1 or Horizon version 31.0.6 or later. OpenNMS is intended for installation in private networks and should not be accessible directly from the Internet, further highlighting the importance of following best practices for network security.

Affected Version(s)

Horizon Windows 31.0.6

Meridian Linux 2020.1.0 < 2020.1.33

Meridian Linux 2021.1.0 < 2021.1.25

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.