299,038
Total vulnerabilities in the database
In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet.
| Software | From | Fixed in |
|---|---|---|
| eclipse / vert.x | 3.0.0 | 3.5.2.x |
io.vertx / vertx-web
|
3.0.0 | 3.5.3 |