{"id":"GHSA-mv73-f69x-444p","summary":"Go Fiber CSRF Token Validation Vulnerability","details":"A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions being taken on the user's behalf, potentially compromising the security and integrity of the application.\n\n## Vulnerability Details\n\nThe vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. The following issues were identified:\n\n1. **Lack of Token Association**: The CSRF token was validated against tokens in storage but was not tied to the original requestor that generated it, allowing for token reuse.\n\n## Remediation\n\nTo remediate this vulnerability, it is recommended to take the following actions:\n\n1. **Update the Application**: Upgrade the application to a fixed version with a patch for the vulnerability.\n\n2. **Implement Proper CSRF Protection**: Review the updated documentation and ensure your application's CSRF protection mechanisms follow best practices.\n\n4. **Choose CSRF Protection Method**: Select the appropriate CSRF protection method based on your application's requirements, either the Double Submit Cookie method or the Synchronizer Token Pattern using sessions.\n\n5. **Security Testing**: Conduct a thorough security assessment, including penetration testing, to identify and address any other security vulnerabilities.\n\n## Defence-in-depth\n\nUsers should take additional security measures like captchas or Two-Factor Authentication (2FA) and set Session cookies with SameSite=Lax or SameSite=Strict, and the Secure and HttpOnly attributes.","aliases":["CVE-2023-45141","GO-2023-2116"],"modified":"2024-02-20T16:04:55Z","published":"2023-10-17T12:41:07Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-10-17T12:41:07Z","nvd_published_at":"2023-10-16T21:15:11Z","cwe_ids":["CWE-352"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/gofiber/fiber/security/advisories/GHSA-mv73-f69x-444p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45141"},{"type":"WEB","url":"https://github.com/gofiber/fiber/commit/8c3916dbf4ad2ed427d02c6eb63ae8b2fa8f019a"},{"type":"WEB","url":"https://github.com/gofiber/fiber/commit/b50d91d58ecdff2a330bf07950244b6c4caf65b1"},{"type":"PACKAGE","url":"https://github.com/gofiber/fiber"}],"affected":[{"package":{"name":"github.com/gofiber/fiber/v2","ecosystem":"Go","purl":"pkg:golang/github.com/gofiber/fiber/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.50.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-mv73-f69x-444p/GHSA-mv73-f69x-444p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}