Vulnerability Description
Taoensso Sente version Prior to version 1.14.0 contains a Cross Site Request Forgery (CSRF) vulnerability in WebSocket handshake endpoint that can result in CSRF attack, possible leak of anti-CSRF token. This attack appears to be exploitable via malicious request against WebSocket handshake endpoint. This vulnerability appears to have been fixed in 1.14.0 and later.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Taoensso | Sente | < 1.14.0 |
Related Weaknesses (CWE)
References
- https://github.com/ptaoussanis/sente/issues/137ExploitIssue TrackingThird Party Advisory
- https://github.com/ptaoussanis/sente/issues/137ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2019-1000022?
CVE-2019-1000022 is a vulnerability with a CVSS score of 8.8 (HIGH). Taoensso Sente version Prior to version 1.14.0 contains a Cross Site Request Forgery (CSRF) vulnerability in WebSocket handshake endpoint that can result in CSRF attack, possible leak of anti-CSRF tok...
How severe is CVE-2019-1000022?
CVE-2019-1000022 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-1000022?
Check the references section above for vendor advisories and patch information. Affected products include: Taoensso Sente.