PyPi: Asgi-Csrf

PVE-2021-38376

Safety vulnerability ID: 38376

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Apr 14, 2021 Updated at Nov 15, 2024

Advisory

Cookie values in asgi-csrf 0.3 are now signed to prevent subdomain attacks. See also: <ht…

[This advisory has been limited. Please create a free account to view the full advisory.]

Affected package

asgi-csrf

Latest version: 0.11

ASGI middleware for protecting against CSRF attacks

Affected versions

Fixed versions

Vulnerability changelog

* Cookie values are now signed to prevent subdomain attacks (described [here](https://che…

[This text has been limited. Please create a free account to view the full text.]

Resources