Description
The console in Togglz before 2.9.4 allows CSRF.
Remediation
References
https://github.com/advisories/GHSA-697v-pxg3-j262
https://github.com/togglz/togglz/commit/ed66e3f584de954297ebaf98ea4a235286784707
https://github.com/togglz/togglz/pull/495
Related Vulnerabilities
CVE-2017-7677 Vulnerability in maven package org.apache.ranger:ranger-hive-utils
CVE-2022-29002 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2023-37949 Vulnerability in maven package io.jenkins.plugins:macstadium-orka
CVE-2020-2211 Vulnerability in maven package com.elasticbox.jenkins-ci.plugins:kubernetes-ci
CVE-2021-29480 Vulnerability in maven package io.ratpack:ratpack-session