HIGH8.8
GHSA-q9qr-jwpw-3qvv
Golf may allow attacker to bypass CSRF protections due to weak PRNG
Quick fix
GHSA-q9qr-jwpw-3qvv — github.com/dinever/golf: upgrade to the fixed version with the command below.
go get github.com/dinever/golf@v0.3.0Details
CSRF tokens are generated using math/rand, which is not a cryptographically secure random number generator, allowing an attacker to predict values and bypass CSRF protections with relatively few requests.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2016-15005[ADVISORY]
- https://github.com/dinever/golf/issues/20[WEB]
- https://github.com/dinever/golf/pull/24[WEB]
- https://github.com/dinever/golf/commit/3776f338be48b5bc5e8cf9faff7851fc52a3f1fe[WEB]
- https://github.com/dinever/golf[PACKAGE]
- https://github.com/dinever/golf/releases/tag/v0.3.0[WEB]
- https://pkg.go.dev/vuln/GO-2020-0045[WEB]