{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2018-25060","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2022-12-30T11:46:16.222Z","datePublished":"2022-12-30T11:47:29.633Z","dateUpdated":"2024-08-05T12:26:39.633Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2023-10-20T12:11:40.501Z"},"title":"Macaron csrf csrf.go missing secure attribute","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-614","lang":"en","description":"CWE-614 Sensitive Cookie Without Secure Attribute"}]}],"affected":[{"vendor":"Macaron","product":"csrf","versions":[{"version":"n/a","status":"affected"}]}],"descriptions":[{"lang":"en","value":"A vulnerability was found in Macaron csrf and classified as problematic. Affected by this issue is some unknown functionality of the file csrf.go. The manipulation of the argument Generate leads to sensitive cookie without secure attribute. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The patch is identified as dadd1711a617000b70e5e408a76531b73187031c. It is recommended to apply a patch to fix this issue. VDB-217058 is the identifier assigned to this vulnerability."},{"lang":"de","value":"Eine Schwachstelle wurde in Macaron csrf gefunden. Sie wurde als problematisch eingestuft. Betroffen davon ist ein unbekannter Prozess der Datei csrf.go. Mittels Manipulieren des Arguments Generate mit unbekannten Daten kann eine sensitive cookie without secure attribute-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Die Komplexität eines Angriffs ist eher hoch. Sie ist schwierig ausnutzbar. Der Patch wird als dadd1711a617000b70e5e408a76531b73187031c bezeichnet. Als bestmögliche Massnahme wird Patching empfohlen."}],"metrics":[{"cvssV3_1":{"version":"3.1","baseScore":3.7,"vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseSeverity":"LOW"}},{"cvssV3_0":{"version":"3.0","baseScore":3.7,"vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseSeverity":"LOW"}},{"cvssV2_0":{"version":"2.0","baseScore":2.6,"vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N"}}],"timeline":[{"time":"2022-12-30T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2022-12-30T00:00:00.000Z","lang":"en","value":"CVE reserved"},{"time":"2022-12-30T01:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2023-01-26T09:25:29.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"VulDB GitHub Commit Analyzer","type":"tool"}],"references":[{"url":"https://vuldb.com/?id.217058","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.217058","tags":["signature","permissions-required"]},{"url":"https://github.com/go-macaron/csrf/pull/7","tags":["issue-tracking"]},{"url":"https://github.com/go-macaron/csrf/commit/dadd1711a617000b70e5e408a76531b73187031c","tags":["patch"]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-05T12:26:39.633Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.217058","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.217058","tags":["signature","permissions-required","x_transferred"]},{"url":"https://github.com/go-macaron/csrf/pull/7","tags":["issue-tracking","x_transferred"]},{"url":"https://github.com/go-macaron/csrf/commit/dadd1711a617000b70e5e408a76531b73187031c","tags":["patch","x_transferred"]}]}]}}