-
Notifications
You must be signed in to change notification settings - Fork 248
Open
Labels
in: integrationstatus: waiting-for-triageWe need additional information before we can continueWe need additional information before we can continue
Description
Marco Redo opened SWF-1749 and commented
It's known that JavaServer Faces' ViewState value can be used as a CSRF token to prevent CSRF attacks.
Anyway, when coupling JavaServer Faces and Spring Web Flow, it seems that the ViewState value loses its anti-CSRF characteristics.
In particular we noticed that:
- the ViewState value is very predictable (e.g.: e1s1, e1s2, e2s1, ...), whilst a CSRF token should be randomly generated
- we're able to repeat the same POST request (inclusive of the ViewState) many times, whilst an anti-CSRF policy should prevent it, maybe causing a response with a 403 error code
Affects: 2.4.2
1 votes, 2 watchers
Metadata
Metadata
Assignees
Labels
in: integrationstatus: waiting-for-triageWe need additional information before we can continueWe need additional information before we can continue