CVE-2022-42975

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/10/2022
Last modified:
10/05/2025

Description

socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffected by default because of the presence of a LiveView CSRF token.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phoenixframework:phoenix:*:*:*:*:*:*:*:* 1.6.14 (excluding)