Eclipse Vert.x是Eclipse基金会的一个用于在JVM上构建响应式应用程序的工具包,它主要用于构建网络实用程序、Web应用程序、HTTP/REST微服务等应用程序。 Eclipse Vert.x 3.0.0版本至3.5.2版本中存在安全漏洞,该漏洞源于CSRFHandler没有断言XSRF Cookie是否匹配返回的XSRF ‘header’/‘form’参数。攻击者可利用该漏洞实施重播攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| The Eclipse Foundation | Eclipse Vert.x | 3.0 ~ unspecified | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Vert.X CSRF Proof of Concept (CVE-2018-12540) | https://github.com/bernard-wagner/vertx-web-xsrf | POC Details |
| 2 | None | https://github.com/tafamace/CVE-2018-12540 | POC Details |
| 3 | None | https://github.com/andikahilmy/CVE-2018-12540-vertx-web-vulnerable | POC Details |
No public POC found.
Login to generate AI POCNo comments yet