PT-2022-24870 · Tiny-Csrf · Tiny-Csrf

Valexandersaulys

·

Published

2022-10-07

·

Updated

2022-10-11

·

CVE-2022-39287

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions tiny-csrf versions prior to 1.1.0
Description The issue concerns the transmission of CSRF tokens in the clear due to unencrypted cookies in versions prior to 1.1.0. This allows malicious attackers to read the tokens. The problem has been addressed, and users are advised to upgrade to version 1.1.0.
Recommendations For versions prior to 1.1.0, upgrade to version 1.1.0 to resolve the issue. As a temporary workaround, consider disabling the use of CSRF tokens until the patch is applied. Restrict access to sensitive operations that rely on CSRF protection to minimize the risk of exploitation.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-39287
GHSA-PJ2C-H76W-VV6F

Affected Products

Tiny-Csrf