Changeset - 9b74296e6af6
stable
0
1
0
auth: further sanitize requests to prevent GET CSRF (CVE-2016-3691)
Routes allows GET requests to override the HTTP method, which breaks
the Kallithea CSRF protection (which only applies to POST requests).
This commit blocks such GET request, preventing CSRF attacks.
Routes allows GET requests to override the HTTP method, which breaks
the Kallithea CSRF protection (which only applies to POST requests).
This commit blocks such GET request, preventing CSRF attacks.
1 file changed with 10 insertions and 0 deletions:
0 comments (0 inline, 0 general)
0 comments (0 inline, 0 general)