Cross-site Request Forgery (CSRF) Affecting com.softwaremill.akka-http-session:core_2.13 Open this link in a new tab package, versions [0,0.6.1)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.Test your applications
21 Jan 2021
24 Nov 2020
How to fix?
com.softwaremill.akka-http-session:core_2.13 to version 0.6.1 or higher.
Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF). CSRF protection can be bypassed by forging a request that contains the same value for both the
X-XSRF-TOKEN header and the
XSRF-TOKEN cookie value, as the check in
randomTokenCsrfProtection only checks that the two values are equal and non-empty.