Headline
GHSA-q9qr-jwpw-3qvv: Golf may allow attacker to bypass CSRF protections
CSRF tokens are generated using math/rand, which is not a cryptographically secure rander number generation, making predicting their values relatively trivial and allowing an attacker to bypass CSRF protections which relatively few requests.
Golf may allow attacker to bypass CSRF protections
Moderate severity GitHub Reviewed Published Dec 28, 2022 • Updated Dec 30, 2022
Related news
CVE-2016-15005: GO-2020-0045 - Go Packages
CSRF tokens are generated using math/rand, which is not a cryptographically secure rander number generation, making predicting their values relatively trivial and allowing an attacker to bypass CSRF protections which relatively few requests.