Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vx94-9hx7-9hmw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. CSRF mitigation can be bypassed because cross-site transmission of a cookie (containing a CSRF token) can occur.

An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. CSRF mitigation can be bypassed because cross-site transmission of a cookie (containing a CSRF token) can occur.

EPSS

Процентиль: 29%
0.00107
Низкий

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. Cross-site transmission of cookie containing CSRF token allows remote attacker to bypass CSRF mitigation.

EPSS

Процентиль: 29%
0.00107
Низкий

Дефекты

CWE-311