CVE-2018-12540

CVE-2018-12540

In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet.

Source: CVE-2018-12540

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다