
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability CVE-2021-3957 affects kimai2, a time-tracking software application. The vulnerability was identified as a Cross-Site Request Forgery (CSRF) issue and was disclosed in November 2021 (CVE Mitre).
The vulnerability is a Cross-Site Request Forgery (CSRF) weakness in kimai2's implementation. The issue specifically affected the log flushing functionality in the DoctorController component, which lacked proper CSRF protection (GitHub Commit).
A successful exploitation of this CSRF vulnerability could allow an attacker to perform unauthorized actions on behalf of authenticated users, specifically related to the log flushing functionality in the application (CVE Mitre).
The vulnerability was patched by implementing CSRF token validation in the log flushing functionality. The fix includes adding CSRF token verification and refreshing mechanisms to prevent unauthorized actions (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."