CVE-2016-7401: CSRF protection bypass on a site with Google Analytics
(updated )
An interaction between Google Analytics and Django’s cookie parsing could allow an attacker to set arbitrary cookies leading to a bypass of CSRF protection.
References
Detect and mitigate CVE-2016-7401 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →