Executive brief
Edgewall Trac is a web-based project management and bug tracking system. A CSRF vulnerability allows remote attackers to perform unauthorized actions (such as modifying tickets, creating comments, or changing project settings) on behalf of authenticated users without their knowledge or consent.
Technical details
A cross-site request forgery (CWE-352) vulnerability exists in Edgewall Trac versions 0.10 and earlier. The vulnerability allows an unauthenticated remote attacker to craft malicious web pages that, when visited by a Trac user, execute unauthorized actions in the user's context without CSRF token protection. The attack requires user interaction (victim must visit a malicious site while authenticated to Trac) but no authentication from the attacker. The vulnerability was fixed in version 0.10.1.
Affected products
- Edgewall Trac 0.10 and earlier
Timeline
- 2006-11-14: disclosed
- 2006: patched: Fixed in Trac 0.10.1