PT-2022-8070 · Unknown+1 · Macaron Csrf+1

Published

2022-12-30

·

Updated

2024-05-17

·

CVE-2018-25060

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Macaron csrf (affected versions not specified)
Description A vulnerability was found in Macaron csrf, classified as problematic. It affects some unknown functionality of the file csrf.go. The manipulation of the argument Generate leads to sensitive cookies without the secure attribute. The attack may be launched remotely. The complexity of an attack is rather high, and the exploitation is known to be difficult.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

CVE-2018-25060
GHSA-HHXG-PX5H-JC32
GO-2022-1213

Affected Products

Debian
Macaron Csrf