CSRF was discovered in the web UI in Deluge before...
Vulnerability Description
CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-7178
Credits & Attribution
No credits recorded in the NVD database.
References
- http://git.deluge-torrent.org/deluge/commit/?h=develop&id=11e8957deaf0c76fdfbac62d99c8b6c61cfdddf9
- http://dev.deluge-torrent.org/wiki/ReleaseNotes/1.3.14
- http://www.securityfocus.com/bid/97041
- https://bugs.debian.org/857903
- http://seclists.org/fulldisclosure/2017/Mar/6
- http://www.debian.org/security/2017/dsa-3856
- https://security.gentoo.org/glsa/201703-06
- http://git.deluge-torrent.org/deluge/commit/?h=1.3-stable&id=318ab179865e0707d7945edc3a13a464a108d583
More from deluge-torrent
View All →Affected Vendor
deluge-torrent
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.