Vulnerabilities/

Incorrect default cookie name and recommendation

Severity:
Low

Description

The default cookie name (and documentation recommendation) was prefixed with Host__ instead of __Host-. The point of this prefix is for additional security, to ensure that, when no domain option is provided in the cookie options, we can guarantee the cookie came from the correct domain.

Recommendation

Update the csrf-csrf package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
csrf-csrf
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing