CVE-2018-12540

EPSS 2.5%

High severity vulnerability that affects io.vertx:vertx-web

發布日:2018/10/17修改日:2024/12/3

描述

In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet.

受影響套件(1)

參考連結(11)