ZeroHour

CVE-2022-39287

CVSS 3.1
6.5 medium
EPSS
<1%p36
Published
()
Modified
Description

tiny-csrf is a Node.js cross site request forgery (CSRF) protection middleware. In versions prior to 1.1.0 cookies were not encrypted and thus CSRF tokens were transmitted in the clear. This issue has been addressed in commit `8eead6d` and the patch with be included in version 1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.

Vendors
tiny-csrf project
Products
tiny-csrf
Weakness
CWE-319
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.