QID 995593

Date Published: 2023-10-18

QID 995593: GO (Go) Security Update for github.com/gofiber/fiber/v2 (GHSA-94w9-97p3-p368)

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to inject arbitrary values and forge malicious requests on behalf of a user. This vulnerability can allow an attacker to inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-94w9-97p3-p368 for updates and patch information.
    Vendor References

    CVEs related to QID 995593

    Software Advisories
    Advisory ID Software Component Link
    GHSA-94w9-97p3-p368 github.com/gofiber/fiber/v2 URL Logo github.com/advisories/GHSA-94w9-97p3-p368