PT-2018-15459 · Hsweb · Hsweb

Publicado

2018-12-30

·

Atualizado

2019-01-14

·

CVE-2018-20595

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions hsweb version 3.0.4
Description A CSRF issue was discovered because the state parameter in the request is not compared with the state parameter in the session after user authentication is successful.
Recommendations For hsweb version 3.0.4, consider modifying the OAuth2ClientController.java to compare the state parameter in the request with the state parameter in the session after user authentication is successful to prevent CSRF attacks.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-20595
GHSA-4RM3-4MQ4-MFWR

Produtos afetados

Hsweb