Описание
Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied token to be considered valid.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.1 (исключая)
cpe:2.3:a:nosurf_project:nosurf:*:*:*:*:*:go:*:*
EPSS
Процентиль: 54%
0.00308
Низкий
7.5 High
CVSS3
Дефекты
CWE-20
Связанные уязвимости
EPSS
Процентиль: 54%
0.00308
Низкий
7.5 High
CVSS3
Дефекты
CWE-20