—
GO-2023-2116
CSRF token validation vulnerability in github.com/gofiber/fiber/v2
Quick fix
GO-2023-2116 — github.com/gofiber/fiber/v2: upgrade to the fixed version with the command below.
go get github.com/gofiber/fiber/v2@v2.50.0Details
A cross-site request forgery vulnerability can allow an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application.
The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The CSRF token is validated against tokens in storage but was is not tied to the original requestor that generated it, allowing for token reuse.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/gofiber/fiber/v2
Introduced in:
0Fixed in: 2.50.0Fix
go get github.com/gofiber/fiber/v2@v2.50.0