CSRF vulnerability in Apache Jackrabbit webdav module (CVE-2016-6801) 

Issue date: 26-04-2018
Affects versions: 11.2, 10.2

Issue ID: SECURITY-36

Affected Product Version(s)
This vulnerability affects all versions of both CMS and delivery applications based on Hippo CMS prior to 11.2.7, and 10.2.11.

Severity 
medium

Description

Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.10.x before 2.10.4 allows remote attackers to hijack the authentication of unspecified victims for requests that create a resource via an HTTP POST request with a (1) missing or (2) crafted Content-Type header. See: CVE-2016-6801

This vulnerability is classified with severity medium. Although the Jackrabbit-webdav module is not used nor formally supported for Hippo CMS, it now is possible to upgrade project specific usages of the module within a Hippo CMS project.

The Apache Jackrabbit version in all supported CMS maintenance versions 10.2.11, 11.2.7, 12.2.1, and 12.3.0 has been updated to 2.16.1.

  • The version used in the 10.2 and 11.2 series was previously 2.10.1.
  • The version used in the 12.2 and 12.3 series was previously 2.14.0.

Instructions

Every CMS customer is strongly advised to upgrade as soon as possible to the latest CMS maintenance release as indicated above, or higher.

Because the upgrade for these CMS maintenance versions may require some additonal steps and verification, specific upgrade documentation is available to our customers for upgrading to version 10.2.11, 11.2.7, or to 12.2.1 and 12.3.0 (login required).