CVE Database
/

CVE-2020-36564

Back to search

CVE-2020-36564

Published: Dec 27, 2022

Modified: Apr 11, 2025

PUBLISHED

Description

Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied token to be considered valid.

VendorProductVersions

github.com/justinas/nosurf

github.com/justinas/nosurf

affected
0 - < 1.1.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now