Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-q9qr-jwpw-3qvv: Golf may allow attacker to bypass CSRF protections

CSRF tokens are generated using math/rand, which is not a cryptographically secure rander number generation, making predicting their values relatively trivial and allowing an attacker to bypass CSRF protections which relatively few requests.

ghsa
#csrf#git

Golf may allow attacker to bypass CSRF protections

Moderate severity GitHub Reviewed Published Dec 28, 2022 • Updated Dec 30, 2022

Related news

CVE-2016-15005: GO-2020-0045 - Go Packages

CSRF tokens are generated using math/rand, which is not a cryptographically secure rander number generation, making predicting their values relatively trivial and allowing an attacker to bypass CSRF protections which relatively few requests.