CVE-2023-45128
Last modified
CVE-2023-45128 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to inject arbitrary values and forge malicious requests on behalf of a user. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to inject arbitrary values and forge malicious requests on behalf of a user. This vulnerability can allow an attacker to inject arbitrary values without any authentication, or perform various malicious actions on behalf of an authenticated user, potentially compromising the security and integrity of the application. The vulnerability is caused by improper validation and enforcement of CSRF tokens within the application. This issue has been addressed in version 2.50.0 and users are advised to upgrade. Users should take additional security measures like captchas or Two-Factor Authentication (2FA) and set Session cookies with SameSite=Lax or SameSite=Secure, and the Secure and HttpOnly attributes as defense in depth measures. There are no known workarounds for this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gofiber | Fiber | < 2.50.0 |
References
- https://github.com/gofiber/fiber/security/advisories/GHSA-94w9-97p3-p368Mitigation, Vendor Advisory
- https://github.com/gofiber/fiber/security/advisories/GHSA-94w9-97p3-p368Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-45128?
How severe is CVE-2023-45128?
How do I fix CVE-2023-45128?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-45122Rejected reason: It is a duplicate.
- CVE-2023-45123Rejected reason: It is a duplicate.
- CVE-2023-45124Rejected reason: It is a duplicate.
- CVE-2023-45125Rejected reason: It is a duplicate.
- CVE-2023-45126Rejected reason: It is a duplicate.
- CVE-2023-45127Rejected reason: It is a duplicate.
- CVE-2023-45129Synapse is an open-source Matrix homeserver written and main…4.9
- CVE-2023-4513BT SDP dissector memory leak in Wireshark 4.0.0 to 4.0.7 and…7.5
- CVE-2023-45130Frontier is Substrate's Ethereum compatibility layer. Prior …7.5
- CVE-2023-45131Discourse is an open source platform for community discussio…7.5
- CVE-2023-45132NAXSI is an open-source maintenance web application firewall…9.8
- CVE-2023-45133Babel is a compiler for writingJavaScript. In `@babel/traver…8.8
Are you affected by CVE-2023-45128?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
