Vulnerability Note VU#555668
JAMF Software Casper Suite contains a cross-site request forgery vulnerability
Overview
JAMF Software's Casper Suite is susceptible to a cross-site request forgery (CSRF) (CWE-352) vulnerability.
Description
JAMF Software's Casper Suite, a Mac OS X and iOS client management framework, contains a cross-site request forgery (CSRF) (CWE-352) vulnerability. The reporter provided a proof-of-concept that created a new user and modified the password for an existing user. |
Impact
By convincing the user to follow a specifically crafted URL, an attacker may be able to execute commands in the context of the logged in user. |
Solution
Apply an Update Casper Suite 8.61 has been released to address this vulnerability. Users should contact JAMF Software to obtain this version. |
Do not click on links |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| JAMF software | Affected | 15 Aug 2012 | 24 Sep 2012 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| Temporal | 5.8 | E:POC/RL:W/RC:C |
| Environmental | 5.8 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
- http://jamfsoftware.com/libraries/pdf/products/documentation/Casper_Suite_8.61_Release_Notes.pdf
- http://jamfsoftware.com/products/casper-suite
- http://cwe.mitre.org/data/definitions/352.html
- http://infosec42.blogspot.com/2012/09/jamf-casper-suite-mdm-csrf-vulnerability.html
Credit
Thanks to Jacob Holcomb for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
- CVE IDs: CVE-2012-4051
- Date Public: 24 Sep 2012
- Date First Published: 24 Sep 2012
- Date Last Updated: 25 Sep 2012
- Document Revision: 21
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.