SBN

The curious case of ‘csrf-magic’: A case study in supply chain poisoning

Back in the day, Ivanti disclosed CVE-2021-44529, a critical “code injection” vulnerability in its EPM Cloud Services Appliance (CSA) product.

*** This is a Security Bloggers Network syndicated blog from Sonatype Blog authored by Ax Sharma. Read the original post at: https://blog.sonatype.com/the-curious-case-of-csrf-magic-a-case-study-in-supply-chain-poisoning