destiny.gg chat vulnerable to cross-site request forgery
High severity
GitHub Reviewed
Published
Dec 22, 2022
to the GitHub Advisory Database
•
Updated Mar 21, 2024
Package
Affected versions
<= 0.0.0-20220628124252-0981d5add8f3
Patched versions
None
Description
Published by the National Vulnerability Database
Dec 22, 2022
Published to the GitHub Advisory Database
Dec 22, 2022
Reviewed
Dec 30, 2022
Last updated
Mar 21, 2024
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in destiny.gg chat. It has been rated as problematic. This issue affects the function websocket.Upgrader of the file main.go. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The name of the patch is bebd256fc3063111fb4503ca25e005ebf6e73780. It is recommended to apply a patch to fix this issue. The identifier VDB-216521 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
References