GSSA-2026-04-4YYSARGITLAB-GSSA-2026-04-4YYSARApril 25, 20264.2 Medium
Missing HSTS and incomplete CSP directives in cobc-events
cobc-events <1.0.1 did not set Strict-Transport-Security and was missing key Content-Security-Policy directives (`frame-ancestors`, `object-src`, `base-uri`, `form-action`), enabling downgrade and clickjacking attacks.
Affected (1)
- gelhaus-solutionscobc-events
- ≥ 0.0.0Fixed in 1.0.1
Mitigations
Workarounds
- Configure HSTS at the reverse proxy or CDN layer.
- Add `X-Frame-Options: DENY` and `Content-Security-Policy: frame-ancestors 'none'` via the proxy.
Solutions
- Upgrade cobc-events to 1.0.1 or later and serve traffic exclusively over HTTPS.
Overview
cobc-events <1.0.1 did not set Strict-Transport-Security and was missing key Content-Security-Policy directives (frame-ancestors, object-src, base-uri, form-action), enabling downgrade and clickjacking attacks.
Severity
CVSS v3
4.2 Medium
4.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- None
- User interaction
- Required
- Scope
- Unchanged
- Confidentiality
- Low
- Integrity
- Low
- Availability
- None
Weaknesses (3)
References (3)
- Patch in src/app.js (Patch)
- MDN: HSTS (Technical description)
- MDN: CSP (Technical description)
Credits (5)
- Enno GelhausFinder · egelhaus@ennogelhaus.de
- Enno GelhausAnalyst · egelhaus@ennogelhaus.de
- Enno GelhausRemediation developer · egelhaus@ennogelhaus.de
- Enno GelhausRemediation reviewer · egelhaus@ennogelhaus.de
- Claude (Anthropic) — automated audit assistantTool · https://claude.com
Context
Impacts
TLS downgrade on first visit
CAPEC-220Clickjacking via iframe embedding
CAPEC-103
Timeline
- 04/25/2026 00:00
Internal security audit started
- 04/25/2026 06:00
Vulnerability identified during audit
- 04/25/2026 12:00
Patch developed and merged to main
- 04/25/2026 14:00
cobc-events 1.0.1 released
- 04/25/2026 15:00
Advisory published