Impact
Weak encryption on CSRF so tokens can be read by malicious attackers.
Patches
Problems have been patched as of v1.1.0
Workarounds
Upgrade to v1.1.0
References
For more information
Submit an issue at the github repo
References:An open API service providing security vulnerability metadata for many open source software ecosystems.
| Affected Packages | Affected Versions | Fixed Versions | |
|---|---|---|---|
|
npm:tiny-csrf
PURL:
pkg:npm/tiny-csrf
|
< 1.1.0 | 1.1.0 | |
Affected Version RangesAll affected versions1.0.0, 1.0.1, 1.0.2, 1.0.3 All unaffected versions1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6 |
|||
Weak encryption on CSRF so tokens can be read by malicious attackers.
Problems have been patched as of v1.1.0
Upgrade to v1.1.0
Submit an issue at the github repo
References: