CVE-2016-8737

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
13/09/2017
Last modified:
20/04/2025

Description

In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site request forgery (CSRF), which could permit a malicious web site to produce a link which, if clicked whilst a user is logged in to Brooklyn, would cause the server to execute the attacker's commands as the user. There is known to be a proof-of-concept exploit using this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:brooklyn:*:*:*:*:*:*:*:* 0.9.0 (including)