{"id":"GHSA-gq67-pp9w-43gp","summary":"Cryptographically weak CSRF tokens in Apache MyFaces","details":"In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.\n\n\nMitigation:\nExisting web.xml configuration parameters can be used to direct\nMyFaces to use SecureRandom for CSRF token generation:\n\norg.apache.myfaces.RANDOM_KEY_IN_VIEW_STATE_SESSION_TOKEN=secureRandom\norg.apache.myfaces.RANDOM_KEY_IN_CSRF_SESSION_TOKEN=secureRandom\norg.apache.myfaces.RANDOM_KEY_IN_WEBSOCKET_SESSION_TOKEN=secureRandom","aliases":["CVE-2021-26296"],"modified":"2026-09-10T03:49:06.075401802Z","published":"2021-06-16T17:31:39Z","database_specific":{"github_reviewed_at":"2021-05-07T21:12:38Z","nvd_published_at":"2021-02-19T09:15:00Z","cwe_ids":["CWE-330","CWE-352"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-26296"},{"type":"WEB","url":"https://github.com/apache/myfaces/commit/cc6e1cc7b9aa17e52452f7f2657b3af9c421b2b2"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/MYFACES-4373"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r2b73e2356c6155e9ec78fdd8f72a4fac12f3e588014f5f535106ed9b%40%3Cannounce.apache.org%3E"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20210528-0007"},{"type":"WEB","url":"http://packetstormsecurity.com/files/161484/Apache-MyFaces-2.x-Cross-Site-Request-Forgery.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2021/Feb/66"}],"affected":[{"package":{"name":"org.apache.myfaces.core:myfaces-core-module","ecosystem":"Maven","purl":"pkg:maven/org.apache.myfaces.core/myfaces-core-module"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.25"}]}],"versions":["2.0.13","2.0.14","2.0.15","2.0.16","2.0.17","2.0.18","2.0.19","2.0.20","2.0.21","2.0.22","2.0.23","2.0.24"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-gq67-pp9w-43gp/GHSA-gq67-pp9w-43gp.json"}},{"package":{"name":"org.apache.myfaces.core:myfaces-core-module","ecosystem":"Maven","purl":"pkg:maven/org.apache.myfaces.core/myfaces-core-module"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"2.1.19"}]}],"versions":["2.1.10","2.1.11","2.1.12","2.1.13","2.1.14","2.1.15","2.1.16","2.1.17","2.1.18","2.1.7","2.1.8","2.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-gq67-pp9w-43gp/GHSA-gq67-pp9w-43gp.json"}},{"package":{"name":"org.apache.myfaces.core:myfaces-core-module","ecosystem":"Maven","purl":"pkg:maven/org.apache.myfaces.core/myfaces-core-module"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"fixed":"2.2.14"}]}],"versions":["2.2.0","2.2.1","2.2.10","2.2.11","2.2.12","2.2.13","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.2.8","2.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-gq67-pp9w-43gp/GHSA-gq67-pp9w-43gp.json"}},{"package":{"name":"org.apache.myfaces.core:myfaces-core-module","ecosystem":"Maven","purl":"pkg:maven/org.apache.myfaces.core/myfaces-core-module"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.3.0"},{"fixed":"2.3.8"}]}],"versions":["2.3-next-M1","2.3-next-M2","2.3-next-M3","2.3-next-M4","2.3-next-M5","2.3-next-M6","2.3-next-M7","2.3-next-M8","2.3-next-M9","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-gq67-pp9w-43gp/GHSA-gq67-pp9w-43gp.json"}}],"schema_version":"1.9.0"}