GHSA-q42q-523g-3fwv
MODERATECVE-2020-7780This affects the package com.softwaremill.akka-http-session:core2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core2.12 before 0.5.11; the package com.softwaremill.akka-http-session:core2.11 before 0.5.11. For older versions, endpoints protected by randomTokenCsrfProtection could be bypassed with an empty X-XSRF-TOKEN header and an empty XSRF-TOKEN cookie.
- Affected
- < 0.5.11
- Fixed in
- 0.5.11
- Weakness
- CWE-352
- Published
- 2022-02-09
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference