Количество 2
Количество 2
CVE-2016-15005
около 3 лет назад
CSRF tokens are generated using math/rand, which is not a cryptographically secure random number generator, allowing an attacker to predict values and bypass CSRF protections with relatively few requests.
CVSS3: 8.8
EPSS: Низкий
GHSA-q9qr-jwpw-3qvv
около 3 лет назад
Golf may allow attacker to bypass CSRF protections due to weak PRNG
CVSS3: 8.8
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2016-15005 CSRF tokens are generated using math/rand, which is not a cryptographically secure random number generator, allowing an attacker to predict values and bypass CSRF protections with relatively few requests. | CVSS3: 8.8 | 0% Низкий | около 3 лет назад | |
GHSA-q9qr-jwpw-3qvv Golf may allow attacker to bypass CSRF protections due to weak PRNG | CVSS3: 8.8 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу
20