CVE-2018-20595

HIGH8.8EPSS 0.08%

Cross-Site Request Forgery (CSRF) in hswebframework.web:hsweb-commons

Published: 1/4/2019Modified: 11/8/2023
Also known as:GHSA-4rm3-4mq4-mfwr

Description

A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the request is not compared with the state parameter in the session after user authentication is successful.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References (5)