Bug 2244664 (CVE-2023-45128)
| Summary: | CVE-2023-45128 golang-github-gofiber-fiber: Cross-Site Request Forgery | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | ybuenos |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | golang-github-gofiber-fiber 2.50.0 | Doc Type: | --- |
| Doc Text: |
A Cross-Site Request Forgery vulnerability has been found in Fiber. Due to improper validation and enforcement of CSRF tokens, an attacker can inject arbitrary values and forge malicious requests on behalf of a user
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2244666, 2244667 | ||
| Bug Blocks: | |||
|
Description
ybuenos
2023-10-17 16:17:28 UTC
Created golang-github-gofiber-fiber-2 tracking bugs for this issue: Affects: fedora-37 [bug 2244666] Affects: fedora-38 [bug 2244667] |