Loading...
Loading...
CSRF does not correctly look into relative URLs in the location header.
in some cases the location header is searched in the configuration as is, and is not found since it doesn't match the wildcard, which can trigger false positive CSRF violations.
There is a relative URL in the location header.
None.
CSRF now correctly looks into relative URLs in the location header.
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.