CVE Published: 12/07/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: eclipse |
Vendor: The Eclipse Foundation |
Product: Eclipse Vert.x Status : PUBLISHED
CVE-2018-12540 Description
In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet.