Debian Security Advisory 3679-1

Debian Linux Security Advisory 3679-1 – Lukas Reschke discovered that Apache Jackrabbit, an implementation of the Content Repository for Java Technology API, did not correctly check the Content-Type header on HTTP POST requests, enabling Cross-Site Request Forgery (CSRF) attacks by malicious web sites.

Leave a Reply