First published: Thu Jul 12 2018(Updated: )
In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet.
Credit: emo@eclipse.org emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Vert.x | >=3.0.0<=3.5.2 | |
redhat/vertex-web | <3.5.3 | 3.5.3 |
maven/io.vertx:vertx-web | >=3.0.0<3.5.3 | 3.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.