This affects the package com.softwaremill.akka-http-session:core2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core2.12 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.11 before 0.5.11. For older versions, endpoints protected by randomTokenCsrfProtection could be bypassed with an empty X-XSRF-TOKEN header and an empty XSRF-TOKEN cookie.
{ "nvd_published_at": "2020-11-27T17:15:00Z", "github_reviewed_at": "2021-04-13T16:52:23Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-352" ] }