VDB
Sign up
HIGH8.8

GHSA-q9qr-jwpw-3qvv

Golf may allow attacker to bypass CSRF protections due to weak PRNG

Quick fix

GHSA-q9qr-jwpw-3qvv — github.com/dinever/golf: upgrade to the fixed version with the command below.

go get github.com/dinever/golf@v0.3.0

Details

CSRF tokens are generated using math/rand, which is not a cryptographically secure random number generator, allowing an attacker to predict values and bypass CSRF protections with relatively few requests.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/dinever/golf
Introduced in: 0Fixed in: 0.3.0
Fixgo get github.com/dinever/golf@v0.3.0

References