Disclosed
CVE-2018-12540
In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet.
Exploitation Probability (EPSS)
Low Priority2.45%
The Exploit Prediction Scoring System (EPSS) uses machine learning to estimate the probability that a vulnerability will be exploited in the wild within the next 30 days.
0% (Theoretical)100% (Certainty)
7-Day Exploitation Trend
Vulnerability Timeline
2 eventsJul 12, 2018
Vulnerability Disclosed
Published to component-level vulnerability database.
Nov 7, 2023
Last Updated
Record updated with new analysis or tags.
Threat Actor Attribution
PREMIUM INTELAssociated Groups:Lazarus Group, APT28
Ransomware Campaigns:LockBit 3.0, BlackCat
IoCs (Indicators):14 IPs, 3 Hashes
Remediation & Mitigation
SOLUTIONOfficial patches and mitigation steps are available for this vulnerability.
# Update Command
apt-get update && apt-get upgrade -y specific-package
# Verify installation
dpkg -l | grep package-name
apt-get update && apt-get upgrade -y specific-package
# Verify installation
dpkg -l | grep package-name
Affected Products
1 Total
eclipse/vert.xAll Versions
References
https://access.redhat.com/errata/RHSA-2018:2371Red Hat
ExploitThird Party Advisory
https://bugs.eclipse.org/bugs/show_bug.cgi?id=536948Eclipse
ExploitVendor Advisory
https://lists.apache.org/thread.html/r10aef585c521f8ef603f5831f9d97a27d920624025131da950e0c62f%40%3Ccommits.pulsar.apache.org%3EApache
https://lists.apache.org/thread.html/r3fffda8e947edaa359152c8dc4c4ea9c96fd8ced1999bbce92bc6b25%40%3Ccommits.pulsar.apache.org%3EApache
Am I Vulnerable?
Check your domain or package.json for CVE-2018-12540 exposure.
Vulnerability Details
CVSS Base Score
6.8/ 10
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Published Date
Jul 12, 2018
Last Modified
Nov 7, 2023
Need Manual Validation?
Automated scanners flag false positives. Get a manual pentest validation for this CVE.