Loading
In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet.
Use CWE-352, Eclipse vendor hub and Vert.X product page to widen CVE-2018-12540 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-17640, CVE-2018-12544 and CVE-2018-12542 for nearby disclosures in the same product family.