CVE-2018-25060
LOW
3,7
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
LOW
2,6
Source: [email protected]
Access Vector: network
Access Complexity: high
Authentication: none
Confidentiality: partial
Integrity: none
Availability: none
Description
AI Translation Available
A vulnerability was found in Macaron csrf and classified as problematic. Affected by this issue is some unknown functionality of the file csrf.go. The manipulation of the argument Generate leads to sensitive cookie without secure attribute. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The patch is identified as dadd1711a617000b70e5e408a76531b73187031c. It is recommended to apply a patch to fix this issue. VDB-217058 is the identifier assigned to this vulnerability.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0016
Percentile
0,4th
Updated
EPSS Score Trend (Last 90 Days)
311
Missing Encryption of Sensitive Data
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Potential Impacts:
Read Application Data
Modify Application Data
Applicable Platforms
All platforms may be affected
614
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
Technologies:
Web Based
Application
Csrf by Go-Macaron
CPE Identifier
View Detailed Analysis
cpe:2.3:a:go-macaron:csrf:-:*:*:*:*:macaron:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/go-macaron/csrf/commit/dadd1711a617000b70e5e408a76531b731870…
https://github.com/go-macaron/csrf/pull/7
https://vuldb.com/?ctiid.217058
https://vuldb.com/?id.217058
https://github.com/go-macaron/csrf/commit/dadd1711a617000b70e5e408a76531b731870…
https://github.com/go-macaron/csrf/pull/7
https://vuldb.com/?ctiid.217058
https://vuldb.com/?id.217058