Phoenix before 1.6.14 mishandles check_origin wildcarding
High severity GitHub Reviewed Published Oct 17, 2022 to the GitHub Advisory Database • Updated May 12, 2025
Description
Published by the National Vulnerability DatabaseOct 17, 2022
Published to the GitHub Advisory Database Oct 17, 2022
Reviewed Oct 18, 2022
Last updated May 12, 2025
socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffected by default because of the presence of a LiveView CSRF token.
References