Cross-site Request Forgery (CSRF) Affecting facebook-sdk package, versions [0.3.0,0.3.2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cross-site Request Forgery (CSRF) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-FACEBOOKSDK-40605
  • published17 Jul 2012
  • disclosed17 Jul 2012
  • creditIshmael Riles

Introduced: 17 Jul 2012

CVE NOT AVAILABLE CWE-352  (opens in a new tab)

Overview

facebook_sdk is a This client library is designed to support the Facebook Graph API and the official Facebook JavaScript SDK, which is the canonical way to implement Facebook authentication. facebook-sdk is vulnerable to cross-site request forgery (CSRF). It does not support the state property in auth urls for CSRF detection, allowing CSRF attacks based on state mutation.

CVSS Scores

version 3.1