Description
The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form value and an empty cookie (if signed cookies are disabled).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57056 | The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form value and an empty cookie (if signed cookies are disabled). |
References
History
Mon, 21 Oct 2024 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Plack\
Plack\ \ |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:plack\:\:middleware\:\:xsrfblock_project:plack\:\:middleware\:\:xsrfblock:*:*:*:*:*:perl:*:* | |
| Vendors & Products |
Plack\
Plack\ \ |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-24T15:40:18.584Z
Reserved: 2024-02-13T00:00:00.000Z
Link: CVE-2023-52431
Updated: 2024-08-02T22:55:41.859Z
Status : Modified
Published: 2024-02-13T05:15:08.797
Modified: 2024-11-21T08:39:44.607
Link: CVE-2023-52431
No data.
OpenCVE Enrichment
No data.
EUVD