The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form value and an empty cookie (if signed cookies are disabled).
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:39
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/briandfoy/cpan-security-advisory/blob/9374f98bef51e1ae887f293234050551c079776f/cpansa/CPANSA-Plack-Middleware-XSRFBlock.yml#L2-L15 - Third Party Advisory | |
References | () https://metacpan.org/release/DAKKAR/Plack-Middleware-XSRFBlock-0.0.19/source/Changes - Release Notes |
21 Oct 2024, 20:19
Type | Values Removed | Values Added |
---|---|---|
First Time |
Plack\ \
Plack\ |
|
CPE | cpe:2.3:a:plack\:\:middleware\:\:xsrfblock_project:plack\:\:middleware\:\:xsrfblock:*:*:*:*:*:perl:*:* | |
References | () https://github.com/briandfoy/cpan-security-advisory/blob/9374f98bef51e1ae887f293234050551c079776f/cpansa/CPANSA-Plack-Middleware-XSRFBlock.yml#L2-L15 - Third Party Advisory | |
References | () https://metacpan.org/release/DAKKAR/Plack-Middleware-XSRFBlock-0.0.19/source/Changes - Release Notes | |
CWE | CWE-352 |
01 Aug 2024, 18:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CWE | CWE-269 |
13 Feb 2024, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-13 05:15
Updated : 2024-11-21 08:39
NVD link : CVE-2023-52431
Mitre link : CVE-2023-52431
CVE.ORG link : CVE-2023-52431
JSON object : View
Products Affected
plack\
- \