drupal/autologout is vulnerable to Cross-Site Request Forgery (CSRF)
50
Medium Risk
Affected versions of this module doesn't sufficiently protect its routes from cross-site request forgery (CSRF), allowing the logout route to be triggered without user interaction.
You are affected if you are using a version that falls within the vulnerable range.
drupal/autologout is vulnerable to Cross-Site Request Forgery (CSRF) in versions 2.0.0 - 2.0.1 and 0.0.1 - 1.6.0.
Upgrade the drupal/autologout library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant