---
title: "CVE-2018-25060\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2018-25060?format=md
keywords: index, follow
---

# CVE-2018-25060

Publication date 30 December 2022

Last updated 26 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**3.7 · Low**

[Score breakdown](https://ubuntu.com/security/CVE-2018-25060?format=md#impact-score)

Toggle side navigation

## Description

A vulnerability was found in Macaron csrf and classified as problematic.
Affected by this issue is some unknown functionality of the file csrf.go.
The manipulation of the argument Generate leads to sensitive cookie without
secure attribute. The attack may be launched remotely. The complexity of an
attack is rather high. The exploitation is known to be difficult. The patch
is identified as dadd1711a617000b70e5e408a76531b73187031c. It is
recommended to apply a patch to fix this issue. VDB-217058 is the
identifier assigned to this vulnerability.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2018-25060?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| golang-github-go-macaron-csrf | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 25.04 plucky | Not in release |
| 24.10 oracular | Not in release |
| 24.04 LTS noble | Not in release |
| 23.10 mantic | Not in release |
| 23.04 lunar | Ignored end of life, was needed |
| 22.10 kinetic | Ignored end of life, was needed |
| 22.04 LTS jammy | Vulnerable |
| 20.04 LTS focal | Vulnerable |
| 18.04 LTS bionic | Vulnerable |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2018-25060?format=md#patch-details)

## Notes

---

### [eslerm](https://launchpad.net/~eslerm)

CVE possibly assigned based on five year old commit message
commit merely changes defaults

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| golang-github-go-macaron-csrf | * Upstream:   [dadd171](https://github.com/go-macaron/csrf/commit/dadd1711a617000b70e5e408a76531b73187031c) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

3.7 · Low

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | Low |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 3.7 · Low |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-25060)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-25060)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2018-25060)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2018-25060)

### Other references

* <https://github.com/go-macaron/csrf/pull/7>
* <https://www.cve.org/CVERecord?id=CVE-2018-25060>
