Weak encryption on CSRF so tokens can be read by malicious attackers.
// patchesProblems have been patched as of v1.1.0
// workaroundsUpgrade to v1.1.0
// referenceshttps://cheatsheetseries.owasp.org/cheatsheets/Cross-SiteRequestForgeryPreventionCheatSheet.html
// for more informationSubmit an issue at the github repo
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- Required
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- None