CVE-2020-28482
19.01.2021, 15:15
This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the httpOnly flag on: cookieOpts: { path: '/', sameSite: true } 2. The CSRF token was available in the GET query parameterEnginsight
Vendor | Product | Version |
---|---|---|
fastify | fastify-csrf | 𝑥 < 3.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration