PT-2024-40138 · Sensiolabs · Sensiolabs/Connect
Published
2024-05-21
·
Updated
2024-05-21
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
sensiolabs/connect versions prior to 4.2.3
Description:
The issue is related to a Cross-Site Request Forgery (CSRF) vulnerability. It occurs due to the absence of the
state parameter in OAuth requests, which exposes applications to CSRF attacks during the OAuth authentication flow.Recommendations:
For versions prior to 4.2.3, update to version 4.2.3 or later to resolve the issue. As a temporary workaround, consider implementing proper
state parameter handling in OAuth requests to prevent CSRF attacks.Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sensiolabs/Connect