Description
A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the request is not compared with the state parameter in the session after user authentication is successful.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0176 | A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the request is not compared with the state parameter in the session after user authentication is successful. |
Github GHSA |
GHSA-4rm3-4mq4-mfwr | Cross-Site Request Forgery (CSRF) in hswebframework.web:hsweb-commons |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:05:17.710Z
Reserved: 2018-12-30T00:00:00.000Z
Link: CVE-2018-20595
No data.
Status : Modified
Published: 2018-12-30T18:29:00.693
Modified: 2024-11-21T04:01:48.800
Link: CVE-2018-20595
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA