Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1305443 | issue tracking vdb entry third party advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177420.html | third party advisory vendor advisory |