In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Cross-site Request Forgery (CSRF) vulnerabilities in an interactive lesson.
Start learningUpgrade invenio-github
to version 1.0.2 or higher.
invenio-github is a "Invenio module that adds GitHub integration to the platform."
Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) due to missing csrftoken
in the API requests.