GHSA-4rm3-4mq4-mfwr
HIGHCVE-2018-20595A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the request is not compared with the state parameter in the session after user authentication is successful.
- Affected
- <= 3.0.4
- Fixed in
- not stated
- Weakness
- CWE-352
- Published
- 2019-01-04
- Source
- github