#4368 pkgdb2 does not protect against Cross Site Request Forgery (CSRF)
Closed: Fixed None Opened 9 years ago by till.

= bug description =

See ticket:992 for CSRF explanation. Pkgdb2 allows to for example drop access with GET requests to URLs like https://admin.fedoraproject.org/pkgdb/acl/libHX/giveup/approveacls/


CSRF is enforced by using forms which we do not do for some of these URLs indeed. I'll look into this.

Fixed in 1.7 which is in stg

Login to comment on this ticket.

Metadata