Reliance on Cookies without Validation Affecting october/rain package, versions >=1.0.319, <1.0.468


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.06% (28th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-OCTOBERRAIN-597171
  • published2 Aug 2020
  • disclosed2 Aug 2020
  • creditUnknown

Introduced: 2 Aug 2020

CVE-2020-15128  (opens in a new tab)
CWE-565  (opens in a new tab)

How to fix?

Upgrade october/rain to version 1.0.468 or higher.

Overview

october/rain is an October Rain Library.

Affected versions of this package are vulnerable to Reliance on Cookies without Validation. Its encrypted cookie values were not tied to the name of the cookie the value belonged to. This meant that certain classes of attacks that took advantage of other theoretical vulnerabilities in user facing code (nothing exploitable in the core project itself) had a higher chance of succeeding.

References

CVSS Scores

version 3.1