CVE-2018-12540

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
12/07/2018
Last modified:
07/11/2023

Description

In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:vert.x:*:*:*:*:*:*:*:* 3.0.0 (including) 3.5.2 (including)