[EP-tech] CSRF Vulnerability in EPrints

Adam Field via Eprints-tech <[email protected]>
Newsgroups gmane.comp.web.eprints.devel
Message-ID <EMEW3|93bc42f2cc8c6f3054e0533d84e19014v2R9uM14eprints-tech-bounces|ecs.soton.ac.uk|[email protected]>
Hi

 

                We’ve had a report from an independent security researcher (Jisc’s policy encourages reporting of issues) that EPrints suffers from a CSRF vulnerability.  The fix for this would be to add tokens to forms so that EPrints can validate that a submitted form was one that it generated.

 

                This is obviously a fairly complex problem to solve, with changes to multiple parts of EPrints, probably requiring a new field type, as well as the storing of tokens somewhere (perhaps a new dataset).  Has anyone taken a look at this?

 

Thanks

 

--

Adam

*** Options: http://mailman.ecs.soton.ac.uk/mailman/listinfo/eprints-tech
*** Archive: http://www.eprints.org/tech.php/
*** EPrints community wiki: http://wiki.eprints.org/
*** EPrints developers Forum: http://forum.eprints.org/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.