VYPR

Fastify Csrf

by Fastify

Source repositories

CVEs (2)

  • CVE-2020-28482MedJan 19, 2021
    risk 0.31cvss 5.9epss 0.01

    This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the httpOnly flag on: cookieOpts: { path: '/', sameSite: true } 2. The CSRF token was available in the GET query parameter

  • CVE-2021-29624MedMay 19, 2021
    risk 0.00cvss 6.5epss 0.01

    fastify-csrf is an open-source plugin helps developers protect their Fastify server against CSRF attacks. Versions of fastify-csrf prior to 3.1.0 have a "double submit" mechanism using cookies with an application deployed across multiple subdomains, e.g. "heroku"-style platform…