ipl/web's `ipl\Web\Common\CsrfCounterMeasure` is susceptible to CSRF
Description
Published to the GitHub Advisory Database
Aug 5, 2024
Reviewed
Aug 5, 2024
Published by the National Vulnerability Database
Aug 5, 2024
Last updated
Aug 6, 2024
Impact
Some of the recent development by Icinga is, under certain circumstances, susceptible to cross site request forgery. (CSRF)
Affected products:
All affected products, in any version, will be unaffected by this once
icinga-php-library
is upgraded.Patches
Version 0.10.1 will include a fix for this. It will be published as part of the
icinga-php-library
v0.14.1 release.References