laptop and a wrench

Bug

There is a Cross-Site Request Forgery (CSRF) vulnerability in Portal for ArcGIS.

Last Published: January 25, 2023 Portal for ArcGIS
Bug ID Number BUG-000148346
SubmittedApril 7, 2022
Last ModifiedApril 20, 2023
Applies toPortal for ArcGIS
Version found10.9.1
Operating SystemN/A
Operating System VersionN/A
Version Fixed11.1
StatusFixed

Additional Information

The Portal for ArcGIS Security 2023 Update 1 Patch is now live on the support site. This is a four-version patch for 10.7.1, 10.8.1, 10.9.1, and 11.0 that addresses both security and non-security issues. The URL is https://support.esri.com/en-us/patches-updates/2023/portal-for-arcgis-security-2023-update-1-patch-8095 Refer to the Issues Addressed section of the patch download page for details on which versions were affected and resolved for each defect.

Workaround

The Portal for ArcGIS Security 2023 Update 1 Patch is now live on the support site. The URL is:

https://support.esri.com/en-us/patches-updates/2023/portal-for-arcgis-security-2023-update-1-patch-8095

Steps to Reproduce

Bug ID: BUG-000148346

Software:

  • Portal for ArcGIS

Get help from ArcGIS experts

Contact technical support

Download the Esri Support App

Go to download options

Discover more on this topic