| - module: github.com/dinever/golf |
| - package: github.com/dinever/golf |
| - Context.RenderFromString |
| CSRF tokens are generated using math/rand, which is not a cryptographically |
| secure random number generator, allowing an attacker to predict values and |
| bypass CSRF protections with relatively few requests. |
| published: 2021-04-14T20:04:52Z |
| - fix: https://github.com/dinever/golf/pull/24 |
| - fix: https://github.com/dinever/golf/commit/3776f338be48b5bc5e8cf9faff7851fc52a3f1fe |
| - report: https://github.com/dinever/golf/issues/20 |
| cwe: 'CWE 338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)' |