Skip to content

Openly visible CSRF tokens in versions prior to v1.1.0

Critical
valexandersaulys published GHSA-pj2c-h76w-vv6f Oct 7, 2022

Package

npm tiny-csrf (npm)

Affected versions

<1.1.0

Patched versions

1.1.0

Description

Impact

Weak encryption on CSRF so tokens can be read by malicious attackers.

Patches

Problems have been patched as of v1.1.0

Workarounds

Upgrade to v1.1.0

References

https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html

For more information

Submit an issue at the github repo

Severity

Critical

CVE ID

CVE-2022-39287

Weaknesses

No CWEs