csrf-csrf vulnerabilities

A utility package to help implement stateless CSRF protection using the Double Submit Cookie Pattern in express.

Direct Vulnerabilities

Known vulnerabilities in the csrf-csrf package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • L
Cross-site Request Forgery (CSRF)

<2.2.1

Package versions

1 - 20 of 20 Results
version published direct vulnerabilities
3.0.6 17 May, 2024
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
3.0.5 15 May, 2024
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
3.0.4 3 Apr, 2024
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
3.0.3 16 Dec, 2023
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
3.0.2 5 Nov, 2023
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
3.0.1 15 Sep, 2023
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
3.0.0 18 Aug, 2023
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
2.3.0 22 Jul, 2023
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
2.2.4 25 Mar, 2023
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
2.2.3 28 Jan, 2023
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
2.2.2 30 Nov, 2022
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
2.2.1 8 Oct, 2022
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
2.2.0 7 Oct, 2022
  • 0
    C
  • 0
    H
  • 0
    M
  • 1
    L
2.1.0 6 Oct, 2022
  • 0
    C
  • 0
    H
  • 0
    M
  • 1
    L
2.0.1 28 Sep, 2022
  • 0
    C
  • 0
    H
  • 0
    M
  • 1
    L
2.0.0 28 Sep, 2022
  • 0
    C
  • 0
    H
  • 0
    M
  • 1
    L
1.0.3 25 Sep, 2022
  • 0
    C
  • 0
    H
  • 0
    M
  • 1
    L
1.0.2 25 Sep, 2022
  • 0
    C
  • 0
    H
  • 0
    M
  • 1
    L
1.0.1 24 Sep, 2022
  • 0
    C
  • 0
    H
  • 0
    M
  • 1
    L
1.0.0 24 Sep, 2022
  • 0
    C
  • 0
    H
  • 0
    M
  • 1
    L