Логотип exploitDog
bind:CVE-2022-39287
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-39287

Количество 2

Количество 2

nvd логотип

CVE-2022-39287

больше 3 лет назад

tiny-csrf is a Node.js cross site request forgery (CSRF) protection middleware. In versions prior to 1.1.0 cookies were not encrypted and thus CSRF tokens were transmitted in the clear. This issue has been addressed in commit `8eead6d` and the patch with be included in version 1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-pj2c-h76w-vv6f

больше 3 лет назад

tiny-csrf has openly visible CSRF tokens

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-39287

tiny-csrf is a Node.js cross site request forgery (CSRF) protection middleware. In versions prior to 1.1.0 cookies were not encrypted and thus CSRF tokens were transmitted in the clear. This issue has been addressed in commit `8eead6d` and the patch with be included in version 1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-pj2c-h76w-vv6f

tiny-csrf has openly visible CSRF tokens

CVSS3: 8.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу