CVE-2024-48913

CVSS V2 None CVSS V3 None
Description
Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Type header. Although the CSRF middleware verifies the Content-Type Header, Hono always considers a request without a Content-Type header to be safe. This can allow an attacker to bypass CSRF protection implemented with Hono CSRF middleware. Version 4.6.5 fixes this issue.
Overview
  • CVE ID
  • CVE-2024-48913
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-10-15T15:56:14.408Z
  • Last Modified Date
  • 2024-10-15T16:15:42.645Z
History
Created Old Value New Value Data Type Notes
2024-10-16 13:09:27 Added to TrackCVE