{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "0.5.11"
              }
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "c4fa80db7304cbd8a1113855a28daf88d92a8fc5"
            },
            {
              "fixed": "57f11663eecb84be03383d164f655b9c5f953b41"
            }
          ],
          "repo": "https://github.com/softwaremill/akka-http-session",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.11 before 0.5.11. For older versions, endpoints protected by randomTokenCsrfProtection could be bypassed with an empty X-XSRF-TOKEN header and an empty XSRF-TOKEN cookie.",
  "id": "CVE-2020-7780",
  "modified": "2026-04-01T23:09:02.050691990Z",
  "published": "2020-11-27T17:15:12.093Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/softwaremill/akka-http-session/issues/77"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/softwaremill/akka-http-session/issues/74"
    },
    {
      "type": "FIX",
      "url": "https://snyk.io/vuln/SNYK-JAVA-COMSOFTWAREMILLAKKAHTTPSESSION-1045352"
    },
    {
      "type": "FIX",
      "url": "https://snyk.io/vuln/SNYK-JAVA-COMSOFTWAREMILLAKKAHTTPSESSION-1046654"
    },
    {
      "type": "FIX",
      "url": "https://snyk.io/vuln/SNYK-JAVA-COMSOFTWAREMILLAKKAHTTPSESSION-1046655"
    },
    {
      "type": "FIX",
      "url": "https://github.com/softwaremill/akka-http-session/commit/57f11663eecb84be03383d164f655b9c5f953b41"
    }
  ],
  "related": [
    "SNYK-JAVA-COMSOFTWAREMILLAKKAHTTPSESSION-1045352",
    "SNYK-JAVA-COMSOFTWAREMILLAKKAHTTPSESSION-1046654",
    "SNYK-JAVA-COMSOFTWAREMILLAKKAHTTPSESSION-1046655"
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}