Description
Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance of this report, stating that "the Apache Tomcat Security team has not accepted any reports of CSRF attacks against the Manager application ... as they require a reckless system administrator.
Remediation
References
http://www.webapp-security.com/wp-content/uploads/2013/11/Apache-Tomcat-5.5.25-CSRF-Vulnerabilities.txt
Related Vulnerabilities
CVE-2020-28501 Vulnerability in npm package es6-crawler-detect
CVE-2018-16487 Vulnerability in npm package @sailshq/lodash
CVE-2022-24999 Vulnerability in maven package org.webjars:qs
CVE-2018-5673 Vulnerability in npm package dojo
CVE-2020-7788 Vulnerability in maven package org.webjars.bowergithub.npm:ini