High severity8.8NVD Advisory· Published Dec 27, 2022· Updated Jun 17, 2026
CVE-2016-15005
CVE-2016-15005
Description
CSRF tokens are generated using math/rand, which is not a cryptographically secure random number generator, allowing an attacker to predict values and bypass CSRF protections with relatively few requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/dinever/golfGo | < 0.3.0 | 0.3.0 |
Affected products
3- github.com/dinever/golf/github.com/dinever/golfv5Range: 0
Patches
Vulnerability mechanics
References
7- github.com/dinever/golf/commit/3776f338be48b5bc5e8cf9faff7851fc52a3f1fenvdPatchThird Party AdvisoryWEB
- github.com/dinever/golf/pull/24nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-q9qr-jwpw-3qvvghsaADVISORY
- github.com/dinever/golf/issues/20nvdIssue TrackingThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2016-15005ghsaADVISORY
- pkg.go.dev/vuln/GO-2020-0045nvdThird Party AdvisoryWEB
- github.com/dinever/golf/releases/tag/v0.3.0ghsaWEB
News mentions
0No linked articles in our index yet.