{"id":"GHSA-q6j3-c4wc-63vw","summary":"CSRF tokens leaked in URL by canned query form","details":"### Impact\n\nThe HTML form for a read-only canned query includes the hidden CSRF token field added in #798 for writable canned queries (#698).\n\nThis means that submitting those read-only forms exposes the CSRF token in the URL - for example on https://latest.datasette.io/fixtures/neighborhood_search submitting the form took me to:\n\nhttps://latest.datasette.io/fixtures/neighborhood_search?text=down&csrftoken=CSRFTOKEN-HERE\n\nThis token could potentially leak to an attacker if the resulting page has a link to an external site on it and the user clicks the link, since the token would be exposed in the referral logs.\n\n### Patches\n\nA fix for this issue has been released in Datasette 0.46.\n\n### Workarounds\n\nYou can fix this issue in a Datasette instance without upgrading by copying the [0.46 query.html template](https://raw.githubusercontent.com/simonw/datasette/0.46/datasette/templates/query.html) into a custom `templates/` directory and running Datasette with the `--template-dir=templates/` option.\n\n### References\n\nIssue 918 discusses this in details: https://github.com/simonw/datasette/issues/918\n\n### For more information\n\nContact swillison at gmail with any questions.","modified":"2024-12-02T05:44:09.099874Z","published":"2020-08-11T14:54:40Z","database_specific":{"cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-08-10T22:36:11Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/simonw/datasette/security/advisories/GHSA-q6j3-c4wc-63vw"},{"type":"WEB","url":"https://github.com/simonw/datasette/issues/918"},{"type":"WEB","url":"https://github.com/simonw/datasette/commit/7f10f0f7664d474c1be82bf668829e3b736a3d2b"},{"type":"PACKAGE","url":"https://github.com/simonw/datasette"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-PYTHON-DATASETTE-598229"}],"affected":[{"package":{"name":"datasette","ecosystem":"PyPI","purl":"pkg:pypi/datasette"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.46"}]}],"versions":["0.10","0.11","0.12","0.13","0.14","0.15","0.16","0.17","0.18","0.19","0.20","0.21","0.22","0.22.1","0.23","0.23.1","0.23.2","0.24","0.25","0.25.1","0.25.2","0.26","0.26.1","0.26.2","0.27","0.27.1","0.28","0.29","0.29.1","0.29.2","0.29.3","0.30","0.30.1","0.30.2","0.31","0.31.1","0.31.2","0.32","0.33","0.34","0.35","0.36","0.37","0.37.1","0.38","0.39","0.40","0.41","0.42","0.43","0.44","0.45","0.45a0","0.45a1","0.45a2","0.45a3","0.45a4","0.45a5","0.8","0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-q6j3-c4wc-63vw/GHSA-q6j3-c4wc-63vw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"}]}