Description
In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0690 | In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet. |
Github GHSA |
GHSA-rvgg-f8qm-6h7j | High severity vulnerability that affects io.vertx:vertx-web |
References
History
No history.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-05T08:38:05.970Z
Reserved: 2018-06-18T00:00:00.000Z
Link: CVE-2018-12540
No data.
Status : Modified
Published: 2018-07-12T14:29:00.273
Modified: 2024-11-21T03:45:23.927
Link: CVE-2018-12540
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA