{"id":"CVE-2022-24947","summary":"Apache JSPWiki CSRF Account Takeover","details":"Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later.","aliases":["GHSA-4284-x26r-4hhc"],"modified":"2026-09-18T11:46:09.150465197Z","published":"2022-02-25T08:30:18Z","database_specific":{"cna_assigner":"apache","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24947.json","unresolved_ranges":[{"extracted_events":[{"introduced":"Apache JSPWiki up to 2.11.1"},{"last_affected":"Apache JSPWiki up to 2.11.1"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread/txrgykjkpt80t57kzpbjo8kfrv8ss02c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24947.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24947"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2022/02/25/1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/jspwiki","events":[{"introduced":"0"},{"fixed":"c85363be9980acc7625dac1fd05e907ebc3e34c2"}],"database_specific":{"cpe":"cpe:2.3:a:apache:jspwiki:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.11.2"}],"source":"CPE_RANGE"}}],"versions":["2.11.1-RC1","2.11.1","2.11.0-RC2","2.11.0","2.11.0-RC1","2.11.0.M8-RC1","2.11.0.M8","2.11.0.M7-RC1","2.11.0.M7","2.11.0.M6-RC1","2.11.0.M6","2.11.0.M5-RC3","2.11.0.M5","2.11.0.M5-RC2","2.11.0.M5-RC1","2.11.0.M4-RC2","2.11.0.M4","2.11.0.M4-RC1","2.11.0.M3-RC2","2.11.0.M3","2.11.0.M3-RC1","2.11.0.M2-RC1","2.11.0.M2","2.11.0.M1.RC3","2.11.0.M1","2.11.0.M1-RC2","2.11.0.M1-RC1","2.10.5-RC2","2.10.5","2.10.5-RC1","2.10.4-RC3","2.10.4","2.10.4-RC2","2.10.4-RC1","2.10.3-RC2","2.10.3","2.10.3-RC1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24947.json"}}],"schema_version":"1.9.0"}