Security Advisories (1)
CVE-2023-52431 (2023-07-14)

When not using signed cookies, it was possible to bypass XSRFBlock by POSTing an empty form value and an empty cookie

Changes for version 0.0.12 - 2017-07-13

  • Refactor internals to make extensible (PR #17)
  • dzil: use Git::Contributors instead of ContributorsFromGit (PR #18)

Documentation

Modules

Block XSRF Attacks with minimal changes to your app